Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.74%—Dell EMC Solutions Enabler Virtual ApplianceDell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell EMC Vasa Provider Virtual Appliance+418/1/202317/6/2026
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system.
ModificadaCrítica (9.8)1.4%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)1.5%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)0.73%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
ModificadaAlta (8.8)0.61%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
ModificadaAlta (8.8)0.61%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
ModificadaAlta (7.5)0.93%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is…
ModificadaMedia (5.8)0.95%—Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Meraki MX Security Appliance Firmware15/11/202211/8/2026
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to…
ModificadaMedia (5.8)0.73%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the…
ModificadaMedia (6.5)0.53%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco Firepower Services Software FOR ASA15/11/202211/8/2026
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a…
ModificadaMedia (6.5)0.84%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…
ModificadaMedia (6.5)0.82%—Cisco Secure Firewall Threat DefenseCisco Umbrella Virtual ApplianceCisco Cyber Vision15/11/202211/8/2026
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to…
ModificadaMedia (6.8)0.34%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.…
ModificadaAlta (7.5)0.83%—Cisco Email Security Appliance4/11/202217/6/2026
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An…
ModificadaMedia (5.3)0.58%—Cisco Email Security Appliance FirmwareCisco Secure Email AND WEB Manager Firmware4/11/202217/6/2026
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker…
ModificadaMedia (6.5)0.45%—IBM MQ Appliance3/11/202217/6/2026
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
ModificadaAlta (8)0.33%—Dell Evasa Provider Virtual ApplianceDell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360+431/8/202217/6/2026
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
ModificadaAlta (7.5)18%💥 PoCCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense10/8/202211/8/2026
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in…
ModificadaMedia (6.1)1.8%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software10/8/202211/8/2026
A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper…
ModificadaCrítica (9.8)0.55%—Quest Kace Systems Management Appliance2/8/202217/6/2026
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
ModificadaAlta (7.5)0.73%—Quest Kace Systems Management Appliance2/8/202217/6/2026
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
ModificadaCrítica (9.8)1.4%—Quest Kace Systems Management Appliance2/8/202217/6/2026
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
ModificadaBaja (3.3)0.20%—IBM Datapower GatewayIBM MQ Appliance M2002 FirmwareIBM MQ Appliance M2001 Firmware1/8/202217/6/2026
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
ModificadaMedia (6.5)0.69%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
ModificadaMedia (6.5)0.69%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.