Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.35%—Viewsonic ViewboardAI5/10/20266/10/2026
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints
AplazadaAlta (7.5)0.27%—Viewsonic ViewboardAI5/10/20266/10/2026
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint
AplazadaAlta (8.2)0.30%—Panasonic Remote I O Coupler UnitAI14/9/202616/9/2026
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.
AplazadaMedia (6.8)0.11%—Panasonic Industry USB DriverAI14/9/202618/9/2026
Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows.
Pendiente de análisisCrítica (9.1)0.68%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
Pendiente de análisisCrítica (9.1)0.46%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
Pendiente de análisisCrítica (9.1)1.6%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,…
AnalizadaCrítica (10)8.8%⚠ Explotación activaSonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware1/9/20263/9/2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
AnalizadaAlta (7.8)11%⚠ Explotación activaSonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware1/9/202621/9/2026
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary…
Pendiente de análisisAlta (7)0.24%—Sonicwall NetextenderAI25/8/202628/8/2026
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
Pendiente de análisisAlta (8.8)0.50%—Sonicwall NetextenderAI25/8/202631/8/2026
A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Pendiente de análisisMedia (5.5)0.16%—Sonicwall Global VPN ClientAI7/8/202628/8/2026
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
AplazadaAlta (8.7)1.6%—Sonic 3 A I RAI6/8/202624/9/2026
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is…
AplazadaAlta (8.3)0.17%—Sonic 3 AIRAI6/8/202624/9/2026
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An…
Pendiente de análisisMedia (6.5)0.34%—Sonicwall SonicosAI5/8/202628/8/2026
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
AnalizadaAlta (7.2)12%⚠ Explotación activaSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
AnalizadaCrítica (10)6.8%⚠ Explotación activaSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
AplazadaMedia (5.5)0.67%—Soniccloudorg Sonic-agentAI12/7/202614/7/2026
A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injection. The attack may…
AplazadaBaja (2.1)2.0%—Soniccloudorg Sonic-agentAI12/7/202613/7/2026
A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results in os command injection. The attack can…
AplazadaBaja (2.1)2.7%—Soniccloudorg Sonic-agentAI12/7/202615/7/2026
A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (4.9)0.50%—Sonicwall Sonicos29/4/202617/6/2026
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
AnalizadaMedia (6.8)0.39%—Sonicwall Sonicos29/4/202617/6/2026
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
AnalizadaAlta (8)0.38%—Sonicwall Sonicos29/4/202617/6/2026
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.