Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Cisco Asyncos | 19/10/2014 | 17/6/2026 | The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934. | |
| Modificada | Media (5.8) | 9.2% | — | Apache HttpclientApache Httpasyncclient | 21/8/2014 | 17/6/2026 | org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle… | |
| Modificada | Media (5) | 6.0% | — | Apache Syncope | 11/7/2014 | 17/6/2026 | Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 10/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (5) | 3.1% | — | Corosync | 6/6/2014 | 16/6/2026 | The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet. | |
| Modificada | Media (4.3) | 1.3% | — | Isync Project Isync | 23/5/2014 | 16/6/2026 | Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 20/5/2014 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085. | |
| Modificada | Alta (7.8) | 4.2% | — | Samba Rsync | 23/4/2014 | 17/6/2026 | The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in the secrets file. | |
| Modificada | Media (4.3) | 1.5% | — | Imapsync Project Imapsync | 18/4/2014 | 17/6/2026 | imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network. | |
| Modificada | Media (5) | 1.8% | — | Imapsync Project Imapsync | 18/4/2014 | 16/6/2026 | imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site. | |
| Modificada | Media (6.5) | 3.3% | — | Apache Syncope | 17/4/2014 | 17/6/2026 | Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings." | |
| Modificada | Alta (7.5) | 1.2% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6) | 0.96% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Alta (7.7) | 0.85% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation. | |
| Modificada | Alta (9) | 4.5% | — | EMC Vplex Geosynchrony | 1/4/2014 | 17/6/2026 | Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.5) | 2.7% | — | Cisco Ironport AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 21/3/2014 | 17/6/2026 | The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root… | |
| Modificada | Baja (3.3) | 0.35% | — | Debian Syncevolution | 28/1/2014 | 17/6/2026 | syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename. | |
| Modificada | Alta (7.5) | 5.5% | — | HP ALM Synchronizer | 4/11/2013 | 16/6/2026 | Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759. | |
| Modificada | Media (4.9) | 0.34% | — | EMC GeosynchronyEMC Vplex GEOEMC Vplex LocalEMC Vplex Metro | 1/10/2013 | 16/6/2026 | EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial… | |
| Modificada | Alta (7.8) | 2.7% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before… | |
| Modificada | Alta (9) | 3.5% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices… | |
| Modificada | Alta (9) | 3.0% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv4, aka Bug ID CSCzv69294. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Synchroweb Synconnect | 28/3/2013 | 16/6/2026 | SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action. | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Synco OZW WEB ServerSiemens Synco OZW WEB Server Firmware | 6/8/2012 | 16/6/2026 | The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session. |