Vulnerabilities

Summary — last 7 days

New vulnerabilities2,840▲ 88 vs. last week
Critical / high1,317▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

19 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedMedium (5.3)——Themesflat FireboxAI10/10/202610/10/2026
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient…
DeferredHigh (8.8)0.94%—Watchguard FireboxAI9/9/20269/9/2026
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to…
DeferredMedium (5.3)0.33%—Firebox PopupsAI6/18/20266/18/2026
The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV export of all form submissions —…
DeferredMedium (6.5)0.19%—Watchguard FireboxAI12/9/202510/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirePlugins FireBox firebox allows Stored XSS.This issue affects FireBox: from n/a through <= 3.1.0-free.
DeferredHigh (8.9)0.32%—Watchguard FireboxAI10/24/202510/8/2026
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
DeferredMedium (4.8)0.48%—Watchguard FireboxAI9/15/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface…
DeferredMedium (4.8)0.54%—Watchguard FireboxAI5/16/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management…
DeferredMedium (4.8)0.55%—Watchguard FireboxAI2/14/20258/8/2026
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of…
DeferredMedium (6.5)1.3%💥 PoCWatchguard Fireware OSAIWatchguard FireboxAIWatchguard XTMAI1/28/20256/17/2026
An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances
ModifiedMedium (5)1.7%—Watchguard Firebox Pptp VPN4/7/20086/16/2026
The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
ModifiedHigh (10)4.3%—RapidstreamWatchguard Firebox4/2/20036/16/2026
Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter.
ModifiedHigh (10)2.8%—RapidstreamWatchguard Firebox4/2/20036/16/2026
The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges.
ModifiedMedium (5)1.7%—Watchguard FireboxWatchguard Soho Firewall10/4/20026/16/2026
Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110.
ModifiedHigh (7.5)1.8%—Watchguard Firebox 2500Watchguard Firebox 45009/20/20016/16/2026
SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.
ModifiedMedium (5)1.3%—Watchguard Firebox II8/2/20016/16/2026
Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets.
ModifiedMedium (5)1.7%—Watchguard Firebox II6/2/20016/16/2026
Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.
ModifiedHigh (10)2.3%—Watchguard Firebox II3/26/20016/16/2026
Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.
ModifiedMedium (5)1.8%—Watchguard Firebox II1/9/20016/16/2026
WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.
ModifiedMedium (5)1.8%—Watchguard Firebox10/20/20006/16/2026
Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.
Orbitaley — Vulnerabilities