Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.86% | — | Cisco Asyncos | 5/2/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator… | |
| Analizada | Media (5.3) | 0.44% | — | Cisco Asyncos | 5/2/2025 | 17/6/2026 | The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware… | |
| Analizada | Media (4.8) | 0.32% | — | Cisco Asyncos | 5/2/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient… | |
| Aplazada | Crítica (9.2) | 0.64% | — | AsynchttpclientAI | 2/12/2024 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name… | |
| Analizada | Media (6.5) | 0.53% | — | Cisco Asyncos | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because confidential information is being… | |
| Analizada | Alta (8.8) | 1.9% | — | Cisco Asyncos | 15/11/2024 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient… | |
| Analizada | Media (5.4) | 0.28% | — | Cisco Asyncos | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability… | |
| Aplazada | Baja (2.3) | 0.58% | — | Cap-stdAICap-std Cap-primitivesAICap-std Cap-async-stdAI | 5/11/2024 | 17/6/2026 | The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write capability-based code. cap-std's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block… | |
| Aplazada | Alta (7.5) | 0.58% | — | Async-graphqlAI | 3/10/2024 | 17/6/2026 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10. | |
| Modificada | Media (6.1) | 0.22% | — | Otasync OTA Sync Booking Engine Widget | 21/8/2024 | 17/6/2026 | The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This is due to missing or incorrect nonce validation on the otasync_widget_settings_fnc() function. This makes it possible for unauthenticated attackers to update the… | |
| Analizada | Alta (7.8) | 0.16% | — | Cisco Asyncos | 17/7/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.2) | 0.62% | — | Cisco Asyncos | 17/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validation in certain portions of the web-based management interface.… | |
| Aplazada | Alta (7.5) | 0.82% | — | AsyncAI | 1/7/2024 | 17/6/2026 | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input. | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based… | |
| Modificada | Alta (8.4) | 0.35% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input.… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco Asyncos | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An… | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (6.8) | 0.87% | — | Asyncssh Project Asyncssh | 14/11/2023 | 17/6/2026 | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack." | |
| Modificada | Media (5.9) | 0.59% | — | Asyncssh Project Asyncssh | 14/11/2023 | 17/6/2026 | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation." | |
| Modificada | Alta (7.5) | 1.2% | — | Freeopcua Opcua-asyncio | 3/10/2023 | 17/6/2026 | Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory. | |
| Modificada | Alta (7.5) | 0.52% | — | Freeopcua Opcua-asyncio | 3/10/2023 | 17/6/2026 | Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session. | |
| Modificada | Alta (7.5) | 0.89% | 💥 PoC | Eminfedar Async-sockets-cpp | 14/8/2023 | 17/6/2026 | async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets. | |
| Modificada | Media (6.1) | 0.38% | — | Syntacticsinc Easync | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Syntactics, Inc. EaSYNC plugin <= 1.3.7 versions. |