Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.35% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints | |
| Aplazada | Alta (7.5) | 0.27% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint | |
| Aplazada | Alta (8.2) | 0.30% | — | Panasonic Remote I O Coupler UnitAI | 14/9/2026 | 16/9/2026 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file. | |
| Aplazada | Media (6.8) | 0.11% | — | Panasonic Industry USB DriverAI | 14/9/2026 | 18/9/2026 | Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows. | |
| Pendiente de análisis | Crítica (9.1) | 0.68% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive. | |
| Pendiente de análisis | Crítica (9.1) | 0.46% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. | |
| Pendiente de análisis | Crítica (9.1) | 1.6% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,… | |
| Analizada | Crítica (10) | 8.8% | ⚠ Explotación activa | Sonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware | 1/9/2026 | 3/9/2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa | Sonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware | 1/9/2026 | 21/9/2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary… | |
| Pendiente de análisis | Alta (7) | 0.24% | — | Sonicwall NetextenderAI | 25/8/2026 | 28/8/2026 | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Sonicwall NetextenderAI | 25/8/2026 | 31/8/2026 | A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Sonicwall Global VPN ClientAI | 7/8/2026 | 28/8/2026 | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash. | |
| Aplazada | Alta (8.7) | 1.6% | — | Sonic 3 A I RAI | 6/8/2026 | 24/9/2026 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is… | |
| Aplazada | Alta (8.3) | 0.17% | — | Sonic 3 AIRAI | 6/8/2026 | 24/9/2026 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Sonicwall SonicosAI | 5/8/2026 | 28/8/2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. | |
| Analizada | Alta (7.2) | 12% | ⚠ Explotación activa | Sonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v | 14/7/2026 | 16/7/2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. | |
| Analizada | Crítica (10) | 6.8% | ⚠ Explotación activa | Sonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v | 14/7/2026 | 16/7/2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | |
| Aplazada | Media (5.5) | 0.67% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 14/7/2026 | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injection. The attack may… | |
| Aplazada | Baja (2.1) | 2.0% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 13/7/2026 | A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results in os command injection. The attack can… | |
| Aplazada | Baja (2.1) | 2.7% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 15/7/2026 | A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (4.9) | 0.50% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. | |
| Analizada | Media (6.8) | 0.39% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. | |
| Analizada | Alta (8) | 0.38% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. |