Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

715 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)6.0%—Ciscoworks Common ServicesCiscoworks LAN Management SolutionCisco QOS Policy ManagerCisco Security Manager+329/10/201016/6/2026
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
ModificadaAlta (7.8)2.2%—F5 Big-ip Protocol Security ModuleF5 Big-ip Application Security ManagerF5 Big-ip Protocol Security Manager24/12/200916/6/2026
Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0 through 10.0.1, and Protocol Security Manager (PSM) 9.4.5 through 9.4.7 and 10.0.0 through 10.0.1, allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: some of…
ModificadaMedia (4.3)4.0%💥 ExploitMcafee Intrushield Network Security Manager13/11/200916/6/2026
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
ModificadaMedia (4.3)2.2%💥 ExploitMcafee Intrushield Network Security Manager13/11/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.
ModificadaAlta (10)13%—Ciscoworks Common ServicesCiscoworks Health AND Utilization MonitorCiscoworks LAN Management SolutionCiscoworks QOS Policy Manager+621/5/200916/6/2026
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows…
ModificadaMedia (6.8)1.4%—Cisco Security Manager22/1/200916/6/2026
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
ModificadaMedia (4.3)7.2%💥 ExploitF5 Big-ip Application Security Manager1/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.
ModificadaBaja (2.1)0.87%—IBM Tivoli Netcool Security Manager15/12/200716/6/2026
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.
ModificadaMedia (4.3)1.2%—IBM Tivoli Netcool Security Manager4/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.6%—Symantec Enterprise Security Manager30/5/200716/6/2026
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.
ModificadaAlta (10)5.4%—Symantec Enterprise Security Manager30/4/200716/6/2026
The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.
ModificadaMedia (5)2.9%—Symantec Enterprise Security Manager23/8/200616/6/2026
The manager server in Symantec Enterprise Security Manager (ESM) 6 and 6.5.x allows remote attackers to cause a denial of service (hang) via a malformed ESM agent request.
ModificadaAlta (7.8)2.0%—Juniper Netscreen-security Manager 200430/12/200516/6/2026
Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).
ModificadaBaja (2.1)5.3%—Entrust Authority Security Manager3/2/200416/6/2026
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
ModificadaMedia (5)1.7%—Netscreen Security ManagerAINetscreen ScreenosAI20/1/200416/6/2026
The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.