Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.4% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access. | |
| Modificada | Alta (7.5) | 6.0% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths. | |
| Modificada | Media (4.8) | 1.1% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product. | |
| Modificada | Alta (8.8) | 1.1% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token. | |
| Modificada | Media (4.8) | 0.72% | — | Trendmicro Interscan WEB Security Virtual Appliance | 17/12/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product in a manner separate from the similar CVE-2020-8462. | |
| Modificada | Alta (7.2) | 45% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (7.2) | 45% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (8.8) | 51% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges. | |
| Modificada | Crítica (9.8) | 73% | — | Trendmicro Interscan WEB Security Virtual Appliance | 18/11/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges. | |
| Modificada | Media (4.7) | 0.93% | — | Cisco Content Security Management ApplianceCisco WEB Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco WEB Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by… | |
| Modificada | Crítica (9.8) | 73% | — | Trendmicro Interscan WEB Security Virtual Appliance | 27/5/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance. | |
| Modificada | Alta (8.8) | 88% | — | Trendmicro Interscan WEB Security Virtual Appliance | 27/5/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability. | |
| Modificada | Alta (7.5) | 90% | — | Trendmicro Interscan WEB Security Virtual Appliance | 27/5/2020 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations. | |
| Modificada | Media (6.1) | 2.0% | — | Trendmicro Interscan WEB Security Virtual Appliance | 27/5/2020 | 17/6/2026 | A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Cloud Email SecurityCisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial… | |
| Modificada | Media (4.9) | 0.87% | — | Cisco Cloud WEB Security | 19/2/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending… | |
| Modificada | Media (6.1) | 3.0% | — | Forcepoint WEB Security | 22/1/2020 | 17/6/2026 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) | |
| Modificada | Alta (7.4) | 0.66% | — | Cisco Ironport WEB Security Appliance | 15/1/2020 | 16/6/2026 | Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks | |
| Modificada | Media (5.9) | 0.58% | — | Cisco Ironport WEB Security Appliance | 15/1/2020 | 16/6/2026 | Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks | |
| Modificada | Media (6.4) | 0.26% | — | Cisco Ironport WEB Security Appliance | 15/1/2020 | 16/6/2026 | Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco AsyncosCisco WEB Security Appliance | 26/11/2019 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in… | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco WEB Security Appliance | 3/5/2019 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of HTTP and HTTPS requests. An attacker could… |