Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)8.5%—Sophos Firewall Firmware21/7/202517/6/2026
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than 21.0 GA.
AnalizadaAlta (8.8)4.8%—Sophos Firewall Firmware21/7/202517/6/2026
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA) auxiliary devices, if OTP authentication for the admin user is enabled.
AnalizadaCrítica (9.8)9.5%—Sophos Firewall Firmware21/7/202517/6/2026
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.
AnalizadaAlta (8.1)7.4%—Sophos Firewall Firmware21/7/202517/6/2026
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.
AnalizadaAlta (7.2)10.0%—Sophos Firewall Firmware21/7/202517/6/2026
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
AnalizadaAlta (8.8)1.3%—Sophos Firewall Firmware19/12/202417/6/2026
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
AnalizadaCrítica (9.8)0.94%—Sophos Firewall Firmware19/12/202417/6/2026
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).
AnalizadaCrítica (9.8)1.4%—Sophos Firewall Firmware19/12/202417/6/2026
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in…
ModificadaCrítica (9.8)1.1%—Gajshield Data Security Firewall Firmware27/4/202317/6/2026
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote…
ModificadaAlta (8.8)0.72%—Sophos XG Firewall Firmware1/12/202217/6/2026
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
ModificadaMedia (4.3)0.75%—Sophos XG Firewall Firmware1/12/202217/6/2026
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
ModificadaBaja (2.7)0.75%—Sophos XG Firewall Firmware1/12/202217/6/2026
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (8.4)0.86%—Sophos XG Firewall Firmware1/12/202217/6/2026
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (7.2)1.2%—Sophos XG Firewall Firmware1/12/202217/6/2026
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (7.2)1.8%—Sophos XG Firewall Firmware1/12/202217/6/2026
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (8.4)0.91%—Sophos Firewall Firmware5/5/202217/6/2026
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
ModificadaAlta (8.4)1.1%—Sophos Firewall Firmware5/5/202217/6/2026
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
ModificadaCrítica (9.8)19%—Cisco Application Extension PlatformCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router Firmware+118/8/202117/6/2026
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This…
ModificadaAlta (7.2)2.2%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware13/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of…
ModificadaAlta (8.8)4.1%—Sophos XG Firewall Firmware7/8/202017/6/2026
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
ModificadaAlta (8.8)3.2%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of…
ModificadaCrítica (9.8)42%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input data by the…
ModificadaCrítica (9.8)3.4%—Cisco Rv110w Wireless-n VPN Firewall Firmware16/7/202017/6/2026
A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. An attacker could…
ModificadaCrítica (9.8)5.7%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router FirmwareCisco Rv215w Wireless-n VPN Router Firmware16/7/202017/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management…
ModificadaAlta (8.8)2.9%—Cisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv215w Firmware16/7/202017/6/2026
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities…