Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.75% | — | Cyberoam Authentication ClientAI | 7/2/2026 | 17/6/2026 | Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with… | |
| Aplazada | Baja (3.8) | 0.23% | — | Mikado-themes RoamAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Roam: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Roamwifi R10AI | 24/4/2024 | 17/6/2026 | Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may obtain sensitive information. | |
| Aplazada | Alta (8.8) | 0.33% | — | Roamwifi R10AI | 24/4/2024 | 17/6/2026 | Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations. | |
| Modificada | Crítica (9.8) | 0.63% | — | Glox Useroam Hotspot | 2/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15. | |
| Modificada | Media (6.1) | 6.9% | — | Cyberoamworks Netgenie C0101b1-20141120-ng11vo Firmware | 17/8/2021 | 17/6/2026 | Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks. | |
| Analizada | Crítica (9.8) | 4.7% | ⚠ Explotación activa | Sophos Cyberoamos | 11/12/2020 | 15/8/2026 | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. | |
| Modificada | Media (4.4) | 0.18% | — | Cisco Umbrella Roaming Client | 23/9/2020 | 17/6/2026 | A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 7.4% | — | Sophos Cyberoamos | 11/10/2019 | 17/6/2026 | A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles. | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Umbrella Enterprise Roaming Client | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system… | |
| Modificada | Alta (7.8) | 1.5% | — | Cisco Umbrella Enterprise Roaming ClientCisco Umbrella Roaming Module | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system… | |
| Modificada | Media (6.1) | 2.0% | — | Sophos Cyberoam Firmware | 7/6/2017 | 17/6/2026 | An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Modificada | Alta (8.8) | 7.0% | — | Sophos Cyberoam Cr25ing UTM Firmware | 7/4/2017 | 17/6/2026 | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5. | |
| Modificada | Media (6.1) | 1.4% | — | Sophos Cyberoam Cr100ing UTM FirmwareSophos Cyberoam Cr35ing UTM Firmware | 6/4/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the… | |
| Modificada | Alta (7.5) | 1.7% | — | Cyberoamos | 4/9/2015 | 17/6/2026 | SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml. | |
| Modificada | Media (6) | 0.56% | — | HP Centralview Fraud Risk ManagementHP Centralview Roaming Fraud ControlHP Centralview Credit Risk ControlHP Centralview Subscription Fraud Prevention+2 | 22/8/2015 | 17/6/2026 | HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0… | |
| Modificada | Media (6) | 0.56% | — | HP Centralview Revenue Leakage ControlHP Centralview Fraud Risk ManagementHP Centralview Subscription Fraud PreventionHP Centralview Dealer Performance Audit+2 | 22/8/2015 | 17/6/2026 | HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0… | |
| Modificada | Alta (9) | 2.1% | — | HP Centralview Revenue Leakage ControlHP Centralview Credit Risk ControlHP Centralview Subscription Fraud PreventionHP Centralview Dealer Performance Audit+2 | 22/8/2015 | 17/6/2026 | HP CentralView Fraud Risk Management 11.1, 11.2, and 11.3; CentralView Revenue Leakage Control 4.1, 4.2, and 4.3; CentralView Dealer Performance Audit 2.0 and 2.1; CentralView Credit Risk Control 2.1, 2.2, and 2.3; CentralView Roaming Fraud Control 2.1, 2.2, and 2.3; and CentralView Subscription Fraud Prevention 2.0… | |
| Modificada | Alta (10) | 2.0% | — | Cyberoam OS | 7/10/2014 | 17/6/2026 | SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode. | |
| Modificada | Alta (9) | 2.3% | — | Cyberoam OS | 7/10/2014 | 17/6/2026 | The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode. | |
| Modificada | Alta (9.3) | 3.7% | — | Cyberoam OS | 7/10/2014 | 17/6/2026 | Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file. | |
| Modificada | Alta (7.4) | 0.94% | — | Elitecore Cyberoam Unified Threat Management | 9/7/2012 | 16/6/2026 | The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of… | |
| Modificada | Alta (7.5) | 2.4% | — | Cyberoam Central Console | 12/2/2012 | 16/6/2026 | Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action. | |
| Modificada | Media (6) | 0.84% | — | Elitecore Cyberoam Unified Threat Management | 4/1/2012 | 16/6/2026 | SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.5% | — | Invisionix Systems Invisionix Roaming System Remote | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter. |