Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.80% | — | Cisco Asyncos | 4/11/2022 | 17/6/2026 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Asyncos | 6/4/2022 | 17/6/2026 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a… | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Asyncos | 17/2/2022 | 17/6/2026 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Asyncos | 4/11/2021 | 17/6/2026 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Asyncos | 6/10/2021 | 17/6/2026 | A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Asyncos | 6/10/2021 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 1.9% | — | Cisco WEB Security ApplianceCisco Asyncos | 8/7/2021 | 17/6/2026 | A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An… | |
| Modificada | Alta (7.4) | 0.67% | — | Cisco Email Security ApplianceCisco AsyncosCisco WEB Security Appliance | 16/6/2021 | 17/6/2026 | A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This… | |
| Modificada | Alta (7.8) | 0.80% | — | Cisco Asyncos | 18/11/2020 | 17/6/2026 | A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Media (5.8) | 1.0% | — | Cisco Asyncos | 8/10/2020 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could… | |
| Modificada | Media (5.3) | 1.9% | — | Cisco Content Security Management ApplianceCisco AsyncosCisco Email Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices,… | |
| Modificada | Alta (8.6) | 1.9% | — | Cisco Email Security ApplianceCisco Asyncos | 23/9/2020 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due… | |
| Modificada | Media (6.5) | 0.88% | — | Cisco Asyncos | 4/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Asyncos | 4/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based… | |
| Modificada | Media (5.8) | 1.4% | — | Cisco Asyncos | 18/6/2020 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could… | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco AsyncosCisco WEB Security Appliance | 26/11/2019 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in… | |
| Modificada | Alta (8.6) | 2.5% | — | Cisco Asyncos | 10/1/2019 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due… | |
| Modificada | Media (5.6) | 1.8% | — | Cisco Asyncos | 8/3/2018 | 17/6/2026 | A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability is due to incorrect FTP user credential validation. An… | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Asyncos | 18/1/2018 | 17/6/2026 | A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Asyncos | 30/11/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a malformed MIME header… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Asyncos | 16/11/2017 | 17/6/2026 | A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Asyncos | 21/9/2017 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the… |