Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.68% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive. | |
| Pendiente de análisis | Crítica (9.1) | 0.46% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. | |
| Pendiente de análisis | Crítica (9.1) | 1.6% | — | Sonicwall Network Security ManagerAI | 4/9/2026 | 8/9/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,… | |
| Aplazada | Media (4.3) | 0.23% | — | Stormshield Network SecurityAI | 2/7/2026 | 2/7/2026 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Stormshield Network SecurityAI | 1/7/2026 | 1/7/2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain… | |
| Pendiente de análisis | Alta (7.1) | 0.31% | — | Trellix Network Security CMAITrellix Network Security NXAI | 26/6/2026 | 29/9/2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details. | |
| Aplazada | Media (5.3) | 0.30% | — | Stormshield Network SecurityAI | 1/6/2026 | 22/7/2026 | A vulnerability was discovered on Stormshield Network Security It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page… | |
| Aplazada | Media (6.8) | 0.13% | — | Infiltrator Network Security ScannerAI | 26/4/2026 | 17/6/2026 | Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a 6000-byte payload into the Scan Target field and trigger a denial of service condition when the Scan button is clicked. | |
| Aplazada | Crítica (9.9) | 0.60% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In… | |
| Aplazada | Media (5.3) | 0.58% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the… | |
| Aplazada | Alta (8.7) | 0.51% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate… | |
| Analizada | Alta (7.5) | 0.34% | — | Stormshield Network Security | 25/9/2025 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing. | |
| Aplazada | Alta (7.3) | 0.29% | — | Stormshield Network SecurityAI | 1/4/2025 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall. | |
| Aplazada | Crítica (9.3) | 1.8% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s… | |
| Aplazada | Alta (8.6) | 1.2% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. | |
| Aplazada | Media (4.2) | 0.20% | — | Stormshield Network SecurityAI | 15/7/2024 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2. | |
| Aplazada | Media (4.2) | 0.17% | — | Stormshield Network SecurityAI | 15/7/2024 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who has access to the SNS with write access on the email alerts page has the ability to create alert email containing malicious JavaScript, executed by the… | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Analizada | Media (4.8) | 0.41% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious… | |
| Analizada | Alta (7.3) | 0.51% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage… | |
| Modificada | Alta (7.5) | 0.29% | — | Stormshield Network Security | 26/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the… | |
| Modificada | Alta (7.5) | 0.53% | — | Stormshield Network Security | 25/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible. | |
| Modificada | Media (6.5) | 0.29% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine. |