Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.21%—IBM MQ Appliance5/5/202317/6/2026
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
ModificadaMedia (6.5)0.71%—IBM MQ Appliance5/5/202317/6/2026
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. IBM X-Force ID: 241354.
ModificadaMedia (6.1)0.41%—Tribe29 Checkmk Appliance Firmware20/4/202317/6/2026
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
ModificadaMedia (5.5)0.22%—Tribe29 Checkmk Appliance Firmware18/4/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
ModificadaMedia (6.1)0.44%—Veritas Netbackup Appliance Firmware10/4/202317/6/2026
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitSophos WEB Appliance4/4/202317/6/2026
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
ModificadaAlta (7.2)1.8%—Sophos WEB Appliance4/4/202317/6/2026
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
ModificadaMedia (5.4)0.57%—Sophos WEB Appliance4/4/202317/6/2026
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
ModificadaAlta (7.5)0.72%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat Defense23/3/202311/8/2026
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote…
ModificadaMedia (5.9)0.68%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco IOSCisco IOS XE23/3/202311/8/2026
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.…
ModificadaAlta (7.4)0.29%—Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS17/3/202317/6/2026
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a…
ModificadaAlta (7.5)0.78%—IBM MQ Appliance10/3/202317/6/2026
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832.
ModificadaMedia (6.7)0.45%💥 PoCCisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaAlta (7.2)1.3%💥 PoCCisco Email Security ApplianceCisco Secure Email AND WEB Manager1/3/202317/6/2026
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user…
ModificadaMedia (6.1)0.69%—Quest Kace Systems Management Appliance1/3/202317/6/2026
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
ModificadaMedia (5.7)0.23%—Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance13/2/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized.
ModificadaAlta (8.8)1.4%—Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance11/2/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system.
ModificadaMedia (4.8)0.34%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server.
ModificadaMedia (6.7)0.42%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root.
ModificadaMedia (6)0.18%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.
ModificadaAlta (8.8)0.31%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions.
ModificadaAlta (7.2)1.7%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote attacker with administrative privileges could potentially exploit the issue and execute commands on the system as the root user.
ModificadaAlta (8.1)0.79%—Dell Powerpath Management Appliance11/2/202317/6/2026
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.
ModificadaBaja (2.7)0.43%—Dell Powerpath Management Appliance10/2/202317/6/2026
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.