Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.34% | — | Sonicwall SonicosAI | 5/8/2026 | 28/8/2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains. | |
| Analizada | Media (4.9) | 0.50% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. | |
| Analizada | Media (6.8) | 0.39% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. | |
| Analizada | Alta (8) | 0.38% | — | Sonicwall Sonicos | 29/4/2026 | 17/6/2026 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | |
| Analizada | Media (4.9) | 0.41% | — | Sonicwall Sonicos | 4/3/2026 | 17/6/2026 | A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. | |
| Analizada | Media (4.9) | 0.36% | — | Sonicwall Sonicos | 24/2/2026 | 17/6/2026 | A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. | |
| Analizada | Media (4.9) | 0.36% | — | Sonicwall Sonicos | 24/2/2026 | 17/6/2026 | A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. | |
| Analizada | Media (4.9) | 0.44% | — | Sonicwall Sonicos | 24/2/2026 | 17/6/2026 | A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. | |
| Analizada | Media (4.9) | 0.33% | — | Sonicwall Sonicos | 24/2/2026 | 17/6/2026 | Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. | |
| Analizada | Alta (7.5) | 1.2% | — | Sonicwall Sonicos | 20/11/2025 | 17/6/2026 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. | |
| Analizada | Crítica (9.8) | 0.91% | — | Sonicwall Sonicos | 29/7/2025 | 17/6/2026 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. | |
| Aplazada | Alta (7.5) | 0.83% | — | Sonicwall SonicosAI | 23/4/2025 | 17/6/2026 | A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload. | |
| Aplazada | Media (4.9) | 0.64% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file. | |
| Aplazada | Alta (7.2) | 0.71% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. | |
| Aplazada | Alta (7.2) | 0.80% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution. | |
| Aplazada | Alta (7.8) | 0.34% | — | Sonicwall SonicoscloudAI | 9/1/2025 | 17/6/2026 | A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution. | |
| Aplazada | Alta (7.5) | 0.74% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa | Sonicwall Sonicos | 9/1/2025 | 4/8/2026 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Sonicwall SonicosAI | 9/1/2025 | 17/6/2026 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass. | |
| Analizada | Crítica (9.8) | 18% | ⚠ Explotación activa | Sonicwall Sonicos | 23/8/2024 | 21/9/2026 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS… | |
| Modificada | Alta (7.5) | 0.70% | — | Sonicwall Sonicos | 18/7/2024 | 17/6/2026 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS). | |
| Modificada | Crítica (9) | 15% | — | FreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos | 9/7/2024 | 17/6/2026 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. | |
| Modificada | Media (6.5) | 0.64% | — | Sonicwall Sonicos | 20/6/2024 | 17/6/2026 | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function. | |
| Modificada | Alta (7.5) | 0.54% | — | Sonicwall Sonicos | 20/6/2024 | 17/6/2026 | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function. |