Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
260 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.93% | — | Juniper IVE OSJuniper Secure Access Virtual ApplianceJuniper Fips Secure Access 4000Juniper Fips Secure Access 4500+13 | 1/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter. | |
| Modificada | Alta (8.5) | 40% | 💥 Exploit | MutinyMutiny Virtual ApplianceMutiny Appliance | 1/6/2013 | 16/6/2026 | Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD… | |
| Modificada | Media (4.7) | 0.32% | — | Juniper Junos SpaceJuniper Junos Space Virtual ApplianceJuniper Junos Space Ja1500 Appliance | 8/5/2013 | 16/6/2026 | Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Sonicwall Aventail SRA EX Virtual ApplianceSonicwall Aventail SRA Ex6000Sonicwall Aventail SRA Ex7000Sonicwall Aventail SRA Ex9000 | 12/2/2013 | 16/6/2026 | SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | |
| Modificada | Baja (3.5) | 0.70% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter. | |
| Modificada | Media (4) | 1.3% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object… | |
| Modificada | Media (6.8) | 0.52% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct… | |
| Modificada | Media (4.3) | 0.86% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the… | |
| Modificada | Alta (10) | 2.7% | — | IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Network Multi-function SecurityIBM Proventia Network Mail Security System Virtual Appliance | 3/4/2009 | 16/6/2026 | Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of… | |
| Modificada | Media (4.3) | 2.2% | — | Trendmicro Interscan WEB Security SuiteTrendmicro Interscan WEB Security Virtual Appliance | 17/2/2009 | 16/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream… |