Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.34%—Sonicwall SonicosAI5/8/202628/8/2026
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
AnalizadaMedia (4.9)0.50%—Sonicwall Sonicos29/4/202617/6/2026
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
AnalizadaMedia (6.8)0.39%—Sonicwall Sonicos29/4/202617/6/2026
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
AnalizadaAlta (8)0.38%—Sonicwall Sonicos29/4/202617/6/2026
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
AnalizadaMedia (4.9)0.41%—Sonicwall Sonicos4/3/202617/6/2026
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
AnalizadaMedia (4.9)0.36%—Sonicwall Sonicos24/2/202617/6/2026
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
AnalizadaMedia (4.9)0.36%—Sonicwall Sonicos24/2/202617/6/2026
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
AnalizadaMedia (4.9)0.44%—Sonicwall Sonicos24/2/202617/6/2026
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
AnalizadaMedia (4.9)0.33%—Sonicwall Sonicos24/2/202617/6/2026
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
AnalizadaAlta (7.5)1.2%—Sonicwall Sonicos20/11/202517/6/2026
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
AnalizadaCrítica (9.8)0.91%—Sonicwall Sonicos29/7/202517/6/2026
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
AplazadaAlta (7.5)0.83%—Sonicwall SonicosAI23/4/202517/6/2026
A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.
AplazadaCrítica (9.8)0.80%—Sonicwall SonicosAI9/1/202517/6/2026
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
AplazadaMedia (4.9)0.64%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
AplazadaAlta (7.2)0.71%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
AplazadaAlta (7.2)0.80%—Sonicwall SonicosAI9/1/202517/6/2026
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
AplazadaAlta (7.8)0.34%—Sonicwall SonicoscloudAI9/1/202517/6/2026
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
AplazadaAlta (7.5)0.74%—Sonicwall SonicosAI9/1/202517/6/2026
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
AnalizadaCrítica (9.8)95%⚠ Explotación activaSonicwall Sonicos9/1/20254/8/2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
AplazadaCrítica (9.8)1.0%—Sonicwall SonicosAI9/1/202517/6/2026
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
AnalizadaCrítica (9.8)18%⚠ Explotación activaSonicwall Sonicos23/8/202421/9/2026
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS…
ModificadaAlta (7.5)0.70%—Sonicwall Sonicos18/7/202417/6/2026
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
ModificadaCrítica (9)15%—FreeradiusBroadcom Brocade SannavBroadcom Fabric Operating SystemSonicwall Sonicos9/7/202417/6/2026
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
ModificadaMedia (6.5)0.64%—Sonicwall Sonicos20/6/202417/6/2026
Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.
ModificadaAlta (7.5)0.54%—Sonicwall Sonicos20/6/202417/6/2026
Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.