Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.5% | — | Cisco Cloud Email SecurityCisco Email Security Appliance | 19/2/2020 | 17/6/2026 | A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Email Security Appliance | 26/1/2020 | 17/6/2026 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of zip files. An attacker could exploit… | |
| Modificada | Media (6.5) | 3.1% | — | ClamavCisco Email Security Appliance FirmwareCanonical Ubuntu LinuxDebian Linux | 15/1/2020 | 17/6/2026 | A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan… | |
| Modificada | Crítica (9.8) | 5.3% | 💥 PoC | Sonicwall Email Security Appliance | 23/12/2019 | 17/6/2026 | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sonicwall Email Security Appliance | 23/12/2019 | 17/6/2026 | Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier. | |
| Modificada | Media (5.3) | 1.0% | — | Cisco Email Security Appliance Firmware | 26/11/2019 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could… | |
| Modificada | Media (4.3) | 0.45% | — | Cisco Email Security Appliance Firmware | 26/11/2019 | 17/6/2026 | A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Email Security Appliance Firmware | 2/10/2019 | 17/6/2026 | A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability exists because the affected software insufficiently… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Email Security Appliance Firmware | 8/8/2019 | 17/6/2026 | A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input and validation checking mechanisms for… | |
| Modificada | Alta (7.4) | 1.2% | — | Cisco Email Security Appliance | 6/7/2019 | 17/6/2026 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input validation of certain email fields. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Email Security Appliance | 6/7/2019 | 17/6/2026 | A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this… | |
| Modificada | Media (5.8) | 1.4% | — | Cisco Email Security Appliance | 20/6/2019 | 17/6/2026 | A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of GZIP-formatted files. An attacker could exploit this… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Email Security Appliance | 3/5/2019 | 17/6/2026 | A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection of certain content sent to an affected device. An attacker… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Email Security Appliance | 18/4/2019 | 17/6/2026 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this… | |
| Modificada | Alta (8.6) | 2.3% | — | Cisco Email Security Appliance Firmware | 10/1/2019 | 17/6/2026 | A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an affected device to corrupt system memory. A… | |
| Modificada | Media (5.3) | 2.3% | — | Cisco Email Security Appliance | 5/10/2018 | 17/6/2026 | A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vulnerability is due to incomplete input and validation checking mechanisms for… | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco Email Security Appliance | 15/8/2018 | 17/6/2026 | A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The vulnerability is due to the improper detection of content within executable (EXE) files. An attacker could… | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Email Security Appliance FirmwareCisco Content Security Management Appliance | 8/2/2018 | 17/6/2026 | A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Email Security Appliance Firmware | 16/11/2017 | 17/6/2026 | A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a HTTP response splitting attack. The vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.3) | 1.3% | — | Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance | 17/8/2017 | 17/6/2026 | A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user.… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Email Security Appliance Firmware | 13/6/2017 | 17/6/2026 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter. More Information: CSCvd34632. Known Affected Releases: 10.0.1-087… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Content Security Management ApplianceCisco Email Security Appliance | 13/6/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device,… | |
| Modificada | Media (5.8) | 1.9% | — | Cisco WEB Security ApplianceCisco Email Security Appliance Firmware | 22/2/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability… | |
| Modificada | Media (5.8) | 2.2% | — | Cisco Email Security Appliance Firmware | 3/2/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device, aka a Malformed MIME Header Filtering Bypass. This vulnerability affects all… | |
| Modificada | Media (5.8) | 1.5% | — | Cisco Email Security Appliance | 26/1/2017 | 17/6/2026 | A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulnerability affects all releases prior to the first fixed release… |