Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.7)0.35%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
AnalizadaAlta (7.7)0.19%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
AnalizadaAlta (7.8)0.48%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
AnalizadaMedia (6.3)0.37%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
AnalizadaMedia (5.3)0.31%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.
AnalizadaMedia (5.3)0.16%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.
AnalizadaMedia (5.3)0.42%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.
AnalizadaMedia (5.3)0.38%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.
AnalizadaMedia (5.3)0.40%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
AnalizadaMedia (6.3)0.42%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.
AnalizadaMedia (4.9)0.38%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.
AnalizadaAlta (8.8)0.17%—IBM Datapower Gateway1/4/202617/6/2026
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…
AnalizadaMedia (6.8)0.25%—IBM Datapower Gateway1/4/202617/6/2026
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.
AnalizadaAlta (7.2)0.61%—Dell Secure Connect Gateway1/4/202617/6/2026
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker within the management network could potentially exploit this vulnerability, leading…
Pendiente de análisisAlta (7.7)0.29%—Citrix Netscaler ADCAICitrix Netscaler GatewayAI23/3/202617/6/2026
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
AnalizadaCrítica (9.3)4.0%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway23/3/202617/6/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
AplazadaMedia (6.4)0.32%💥 PoCMinhnhut Link GatewayAI21/3/202617/6/2026
The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.18%—IBM Sterling B2B IntegratorIBM Sterling File Gateway17/3/202617/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.
AnalizadaAlta (7.5)0.34%—IBM Sterling B2B IntegratorIBM Sterling File Gateway17/3/202617/6/2026
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.
AplazadaBaja (2.1)0.52%—ThingsgatewayAI16/3/202617/6/2026
A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The manipulation of the argument fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about…
AnalizadaAlta (7.1)0.21%—IBM Cics Transaction Gateway16/3/202617/6/2026
IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to improper access controls.
AplazadaMedia (5.3)0.29%—Linknacional Payment Gateway PIX FOR GivewpAI13/3/202617/6/2026
Missing Authorization vulnerability in linknacional Payment Gateway Pix For GiveWP payment-gateway-pix-for-givewp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Pix For GiveWP: from n/a through <= 2.2.3.
AnalizadaMedia (5.4)0.21%—IBM Sterling B2B IntegratorIBM Sterling File Gateway13/3/202617/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…
AnalizadaAlta (7.2)0.31%—IBM Sterling B2B IntegratorIBM Sterling File Gateway13/3/202617/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information…
AnalizadaMedia (5.4)0.21%—IBM Sterling B2B IntegratorIBM Sterling File Gateway13/3/202617/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…
Orbitaley — Vulnerabilidades