Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.11%—Aruba Clearpass Policy Manager OnguardAI6/10/20267/10/2026
A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.
AplazadaMedia (6.3)0.30%—Chainguard ApkoAI5/10/20266/10/2026
apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On…
En análisisCrítica (9.3)0.14%—Watchguard Kernel Memory Access DriverAI1/10/20262/10/2026
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process…
AnalizadaAlta (8.7)0.38%—Watchguard Fireware30/9/20266/10/2026
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
AnalizadaAlta (7.1)0.23%—Watchguard Fireware29/9/20266/10/2026
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted…
AnalizadaAlta (7.1)0.30%—Watchguard Fireware29/9/20266/10/2026
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted…
AnalizadaAlta (8.2)0.35%—Watchguard Fireware29/9/20266/10/2026
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
AnalizadaAlta (8.2)0.36%—Watchguard Fireware29/9/20266/10/2026
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
AnalizadaCrítica (9.2)0.42%—Watchguard Fireware29/9/20266/10/2026
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
AnalizadaAlta (8.2)0.36%—Watchguard Fireware29/9/20266/10/2026
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
AnalizadaMedia (6)0.31%—Watchguard Fireware29/9/20266/10/2026
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
AnalizadaAlta (8.7)0.36%—Watchguard Fireware29/9/20266/10/2026
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
En análisisAlta (7.2)0.23%—Watchguard FirewareAI29/9/202630/9/2026
An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.
AplazadaAlta (8.7)0.20%—Watchguard FirewareAI29/9/20261/10/2026
A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.
En análisisAlta (8.6)0.34%—Watchguard FirewareAI29/9/20261/10/2026
A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.
En análisisAlta (7.1)0.23%—Watchguard Fireware OSAI29/9/202630/9/2026
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.
En análisisAlta (8.2)0.36%—Watchguard Fireware OSAI29/9/202630/9/2026
A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
En análisisAlta (7.5)0.32%—Watchguard Fireware OSAI29/9/20261/10/2026
A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted…
AnalizadaAlta (8.1)0.39%—IBM Guardium Data Protection29/9/20261/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
AnalizadaAlta (8.8)0.74%—IBM Guardium Data Protection29/9/20261/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
AnalizadaCrítica (9.1)0.68%—IBM Guardium Data Protection29/9/20262/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
AnalizadaAlta (7.2)0.68%—IBM Guardium Data Protection29/9/20262/10/2026
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
AplazadaAlta (8.6)1.2%—Watchguard APAI28/9/202628/9/2026
An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.
AplazadaCrítica (9.3)2.0%—Watchguard APAI28/9/202628/9/2026
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
AplazadaCrítica (9.3)0.27%—Watchguard Access PointAI28/9/202628/9/2026
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Orbitaley — Vulnerabilidades