Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. | |
| Analizada | Media (5.3) | 0.38% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions. | |
| Analizada | Media (5.3) | 0.40% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. | |
| Analizada | Media (6.3) | 0.42% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails. | |
| Analizada | Media (4.9) | 0.38% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users. | |
| Aplazada | Alta (8.6) | 0.30% | — | Omnissa Secure Email GatewayAI | 11/8/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks. | |
| Analizada | Media (5.3) | 0.36% | — | Cisco Secure Email Gateway | 19/2/2025 | 17/6/2026 | This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device. | |
| Aplazada | Alta (7.5) | 0.65% | — | Zertificon Z1 SecuremailAIZertificon Z1 Securemail GatewayAI | 12/2/2025 | 17/6/2026 | An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensitive information via the /compose-pdf.xhtml?convid=[id] component. | |
| Aplazada | Media (4.3) | 0.34% | — | Cisco Secure Email AND WEB ManagerAICisco Secure Email GatewayAICisco Secure WEB ApplianceAI | 5/2/2025 | 17/6/2026 | A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists… | |
| Analizada | Crítica (9.8) | 1.4% | — | Cellopoint Secure Email Gateway | 20/9/2024 | 17/6/2026 | Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing authentication and obtaining system administrator privileges. | |
| Analizada | Crítica (9.8) | 2.3% | — | Cisco Secure Email Gateway | 17/7/2024 | 17/6/2026 | A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handling of email attachments when file analysis and content… | |
| Modificada | Crítica (9.8) | 0.77% | — | Cellopoint Secure Email Gateway | 15/7/2024 | 17/6/2026 | The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server. | |
| Modificada | Crítica (9.8) | 0.71% | 💥 PoC | Cisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware | 10/1/2024 | 17/6/2026 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | |
| Modificada | Alta (8.8) | 1.4% | — | Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment | 27/9/2023 | 17/6/2026 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… | |
| Modificada | Media (5.4) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,… | |
| Modificada | Alta (7.1) | 1.5% | 💥 Exploit | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow… | |
| Modificada | Media (4.3) | 0.98% | — | Mcafee Email Gateway | 16/9/2020 | 17/6/2026 | Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a restricted directory. | |
| Modificada | Media (6.1) | 0.85% | — | Kaspersky Secure Mail Gateway | 6/2/2018 | 17/6/2026 | WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1. | |
| Modificada | Alta (7.8) | 0.48% | — | Kaspersky Secure Mail Gateway | 6/2/2018 | 17/6/2026 | Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1. | |
| Modificada | Crítica (9.8) | 6.6% | — | Kaspersky Secure Mail Gateway | 6/2/2018 | 17/6/2026 | Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1. | |
| Modificada | Alta (8.8) | 0.64% | — | Kaspersky Secure Mail Gateway | 6/2/2018 | 17/6/2026 | Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1. | |
| Modificada | Media (6.1) | 0.88% | — | Proxmox Mail Gateway | 3/5/2017 | 17/6/2026 | Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter. |