Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
ModificadaMedia (4.6)0.18%—Teradici Pcoip Connection Manager AND Security Gateway6/4/202117/6/2026
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3.
ModificadaMedia (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaAlta (7.5)1.3%—Checkpoint Security Gateway2/10/201917/6/2026
In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.
ModificadaCrítica (9.8)17%—Sophos Astaro Security Gateway Firmware19/9/201717/6/2026
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
ModificadaMedia (5.3)1.7%—Oracle Communications Security Gateway24/4/201717/6/2026
Vulnerability in the Oracle Communications Security Gateway component of Oracle Communications Applications (subcomponent: Network). The supported version that is affected is 3.0.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via ICMP Ping to compromise Oracle Communications…
ModificadaMedia (6.5)2.2%—Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE29/11/201617/6/2026
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.…
ModificadaAlta (7.1)0.85%—Huawei Unified Security Gateway Firmware7/12/201517/6/2026
Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DHCP Snooping" is enabled and either "option82 insert" or "option82 rebuild" is enabled on an interface, allow remote attackers to cause a denial of service (reboot) via crafted DHCP packets.
ModificadaMedia (4.3)2.5%—Websense Triton AP WEBWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+125/3/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML…
ModificadaAlta (7.1)1.5%—Checkpoint Security Gateway16/11/201417/6/2026
Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Network Extender, (5) Identify Awareness blade, (6) HTTPS Inspection, (7) UserCheck, or (8) Data Leak…
ModificadaAlta (7.1)1.5%—Checkpoint Security Gateway16/11/201417/6/2026
Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0 process crash, core…
ModificadaAlta (7.1)1.5%—Checkpoint Security Gateway16/11/201417/6/2026
Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors involving an HTTPS request.
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
ModificadaBaja (3.5)1.3%—Websense Triton Unified Security CenterWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+112/4/201417/6/2026
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext…
ModificadaAlta (10)1.4%—Checkpoint Security Gateway1/4/201417/6/2026
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600 and 1100 appliances R75.20.x before R75.20.42 have unknown impact and attack vectors related to "important security fixes."
ModificadaMedia (4)0.85%—Checkpoint Management ServerCheckpoint Security Gateway26/1/201417/6/2026
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions.
ModificadaMedia (5)1.4%—Matrikonopc Security Gateway1/5/201316/6/2026
The configuration utility in MatrikonOPC Security Gateway 1.0 allows remote attackers to cause a denial of service (unhandled exception and application crash) via a TCP RST packet.
ModificadaAlta (7.5)3.5%—Websense WEB FilterWebsense WEB SecurityWebsense WEB Security GatewayWebsense WEB Security Gateway Anywhere23/8/201216/6/2026
The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows…
ModificadaMedia (4.3)3.5%—Astaro Security Gateway SoftwareAstaro Security GatewaySophos Unified Threat Management SoftwareSophos Unified Threat Management9/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.