Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.2%—Websense WEB SecurityWebsense WEB Filter23/8/201216/6/2026
The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers to cause a denial of service (daemon exit) via a large volume of traffic.
ModificadaBaja (2.1)0.39%—Websense WEB SecurityWebsense WEB Filter23/8/201216/6/2026
The Remote Filtering component in Websense Web Security and Web Filter before 7.1 Hotfix 66 allows local users to bypass filtering by (1) renaming the WDC.exe file or (2) deleting driver files.
ModificadaMedia (4.3)1.3%—Websense WEB FilterWebsense WEB Security23/8/201216/6/2026
The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 136 and 7.x before 7.1.1 on Windows allows remote attackers to cause a denial of service (filtering outage) via a crafted sequence of characters in a URI.
ModificadaMedia (4.3)1.5%—WebsenseWebsense WEB SecurityWebsense WEB Filter23/8/201216/6/2026
The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header.
ModificadaMedia (4.3)0.94%—Websense WEB FilterWebsense WEB Security23/8/201216/6/2026
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a…
ModificadaMedia (4.3)1.1%—Websense WEB FilterWebsense WEB Security23/8/201216/6/2026
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted…
ModificadaAlta (10)3.9%—Mcafee Smartfilter Administration22/8/201216/6/2026
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.
ModificadaMedia (6.8)0.86%—Symantec Message Filter5/7/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.
ModificadaMedia (4.3)1.5%—Symantec Message Filter5/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.77%—Symantec Message Filter5/7/201216/6/2026
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaBaja (3.3)0.81%—Symantec Message Filter5/7/201216/6/2026
Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.
ModificadaMedia (6.8)0.60%—Bloxx WEB Filtering9/6/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error pages containing XSS sequences, a different vulnerability than…
ModificadaMedia (5)2.1%—Bloxx WEB Filtering9/6/201216/6/2026
Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header.
ModificadaMedia (5.8)1.2%—Bloxx WEB Filtering9/6/201216/6/2026
Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.
ModificadaMedia (6.8)0.77%—Bloxx WEB Filtering9/6/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bloxx Web Filtering before 5.0.14 allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions.
ModificadaMedia (4.3)1.3%—Bloxx WEB Filtering9/6/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Bloxx Web Filtering before 5.0.14 allow (1) remote attackers to inject arbitrary web script or HTML via web traffic that is examined within the Bloxx Reports component, and allow (2) remote authenticated administrators to inject arbitrary web script or HTML via…
ModificadaMedia (6.4)1.0%—Androidapptools Easy Filter25/1/201216/6/2026
The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.
ModificadaMedia (5.8)1.1%—In-mediakg Filterftp27/4/201116/6/2026
Directory traversal vulnerability in FilterFTP 2.0.3, 2.0.5, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)4.0%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers…
ModificadaAlta (9.3)3.3%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
The SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via unspecified vectors related to allocation of an array of pointers and "string indexing," which triggers memory corruption.
ModificadaAlta (9.3)4.0%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
Heap-based buffer overflow in the WordPerfect 5.x reader (wosr.dll), as used in Autonomy KeyView 10.4 and 10.9 and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to "data blocks."
ModificadaAlta (9.3)4.0%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
Integer signedness error in rtfsr.dll in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted \ls keyword in a list override table entry in an RTF file, which triggers a buffer overflow.
ModificadaAlta (9.3)4.0%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allow remote attackers to execute arbitrary code via unspecified vectors related to "certain records."
ModificadaAlta (9.3)4.1%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKSymantec Mail Security17/8/201016/6/2026
Stack-based buffer overflow in the SpreadSheet Lotus 123 reader (wkssr.dll), as used in Autonomy KeyView 10.4 and 10.9, Symantec Mail Security, and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to floating point conversion in unknown record types.
ModificadaAlta (9.3)4.0%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK17/8/201016/6/2026
Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted compound file, as demonstrated using a Quattro Pro file, which is not properly handled by the Quattro speed…
Orbitaley — Vulnerabilidades