Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Checkpoint Identity AwarenessAICheckpoint Security GatewayAI | 26/5/2026 | 24/7/2026 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. | |
| Aplazada | Baja (2.7) | 0.35% | — | Hillstone Networks Operation AND Maintenance Security GatewayAI | 4/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113. | |
| Analizada | Media (6.1) | 1.9% | ⚠ Explotación activa | Libraesva Email Security Gateway | 19/9/2025 | 17/6/2026 | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has… | |
| Aplazada | Alta (8.8) | 0.63% | — | Daikin Security GatewayAI | 11/9/2025 | 17/6/2026 | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Titanhq Spamtitan Email Security GatewayAI | 21/8/2025 | 17/6/2026 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided… | |
| Aplazada | Alta (8.8) | 0.70% | — | Mingyu Security GatewayAI | 17/7/2025 | 17/6/2026 | Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds. | |
| Analizada | Media (5.3) | 0.60% | — | Netentsec Application Security Gateway | 15/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The manipulation of the argument messagecontent leads to sql injection. It is possible to initiate the attack remotely.… | |
| Analizada | Media (5.3) | 0.65% | — | Netentsec Application Security Gateway | 9/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/firewall/deletemacbind.php. The manipulation of the argument messagecontent leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.68% | — | Netentsec Application Security Gateway | 9/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. This issue affects some unknown processing of the file /protocol/iscuser/deleteiscuser.php. The manipulation of the argument messagecontent leads to sql injection. The attack may be initiated… | |
| Analizada | Media (5.3) | 0.61% | — | Netentsec Application Security Gateway | 3/6/2024 | 17/6/2026 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability affects unknown code of the file /protocol/iscuser/uploadiscuser.php of the component JSON Content Handler. The manipulation of the argument messagecontent leads to sql injection. The… | |
| Analizada | Media (5.3) | 0.54% | — | Netentsec Application Security Gateway | 3/6/2024 | 17/6/2026 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /admin/config_MT.php?action=delete. The manipulation of the argument Mid leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Analizada | Crítica (9.8) | 0.71% | — | Netentsec Application Security Gateway | 8/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 0.68% | — | Netentsec Application Security Gateway | 8/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The manipulation of the argument GroupId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.76% | — | Netentsec Application Security Gateway | 8/4/2024 | 17/6/2026 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/config_Anticrack.php. The manipulation of the argument GroupId leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.73% | — | Netentsec Application Security Gateway | 8/4/2024 | 17/6/2026 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely.… | |
| Aplazada | Media (6.5) | 0.17% | — | Byzoro Networks Smart Multi-service Security Gateway Intelligent Management PlatformAI | 4/4/2024 | 17/6/2026 | File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component. | |
| Analizada | Crítica (9.8) | 0.82% | — | Netentsec Application Security Gateway | 28/3/2024 | 17/6/2026 | A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 0.82% | — | Netentsec Application Security Gateway | 28/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. The manipulation of the argument CRLId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Alta (7.8) | 0.33% | — | Netentsec Application Security Gateway Firmware | 21/3/2024 | 17/6/2026 | SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component. | |
| Analizada | Crítica (9.8) | 0.84% | — | Netentsec Application Security Gateway | 20/3/2024 | 17/6/2026 | A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /protocol/iscdevicestatus/deleteonlineuser.php. The manipulation of the argument messagecontent leads to sql injection. The attack can… | |
| Analizada | Media (5.3) | 0.73% | — | Netentsec Application Security Gateway | 19/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath expressions. It is possible to launch the… | |
| Analizada | Crítica (9.8) | 0.95% | — | Netentsec Application Security Gateway | 19/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. This issue affects some unknown processing of the file /admin/singlelogin.php. The manipulation of the argument loginId leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.81% | — | Netentsec Application Security Gateway | 19/3/2024 | 17/6/2026 | A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /vpnweb/index.php?para=index. The manipulation of the argument check_VirtualSiteId leads to sql injection. The attack can be initiated remotely. The exploit has… |