Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 2.3% | — | Moxa Nport 5100 Series FirmwareMoxa Nport 5200 Series FirmwareMoxa Nport 5400 Series FirmwareMoxa Nport 5600 Series Firmware+6 | 13/2/2017 | 17/6/2026 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series… | |
| Modificada | Crítica (9.8) | 20% | — | Moxa Nport 5100 Series FirmwareMoxa Nport 5200 Series FirmwareMoxa Nport 5400 Series FirmwareMoxa Nport 5600 Series Firmware+6 | 13/2/2017 | 17/6/2026 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series… | |
| Modificada | Baja (3.3) | 0.39% | — | Moxa Nport 5100 Series FirmwareMoxa Nport 5200 Series FirmwareMoxa Nport 5400 Series FirmwareMoxa Nport 5600 Series Firmware+6 | 13/2/2017 | 17/6/2026 | An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series… | |
| Modificada | Media (5) | 1.2% | — | Cisco Ironport Email Security Appliances | 19/12/2014 | 17/6/2026 | The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 10/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or… | |
| Modificada | Alta (8.5) | 2.7% | — | Cisco Ironport AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 21/3/2014 | 17/6/2026 | The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial… | |
| Modificada | Alta (7.8) | 2.7% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before… | |
| Modificada | Alta (9) | 3.5% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices… | |
| Modificada | Alta (9) | 3.0% | — | Cisco Ironport Asyncos | 27/6/2013 | 16/6/2026 | The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv4, aka Bug ID CSCzv69294. | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Ironport Encryption Appliance | 13/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitrary web script or HTML via the header parameter to the default URI under admin/, aka bug ID 72410. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Dev!l's Dev!l'z Clanportal Gamebase Addon | 20/1/2012 | 16/6/2026 | SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a detail action to index.php. | |
| Modificada | Media (5) | 1.1% | — | Cisco Ironport Desktop Flag Plugin FOR Outlook | 14/5/2010 | 16/6/2026 | The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intended to be encrypted, aka bug 65623. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Dzcp Dev!l'z Clanportal | 16/3/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter. | |
| Modificada | Alta (10) | 4.4% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka IronPort Bug 65923. | |
| Modificada | Alta (7.8) | 0.88% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65922. | |
| Modificada | Alta (7.8) | 0.88% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65921. | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Ironport AsyncosCisco Ironport Email Security Appliances | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Aspindir Batmanportal | 7/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 0.55% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers… | |
| Modificada | Media (6.8) | 0.45% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers… | |
| Modificada | Media (4.3) | 0.79% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified… | |
| Modificada | Media (4.3) | 0.79% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to… | |
| Modificada | Media (5.1) | 1.9% | 💥 Exploit | Justin ROY Punportal Module | 10/12/2008 | 16/6/2026 | Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dev!l's Clanportal | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action. |