Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.64% | — | Cisco WEB Security Appliance | 3/5/2019 | 17/6/2026 | A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The vulnerability is due to insufficient validation of user-supplied input on the web and command-line interface. An… | |
| Modificada | Alta (8.8) | 1.5% | — | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2019 | 17/6/2026 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability. | |
| Modificada | Media (5.8) | 1.6% | — | Cisco WEB Security Appliance | 8/2/2019 | 17/6/2026 | A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of… | |
| Modificada | Media (6.7) | 0.44% | — | Cisco WEB Security Appliance | 15/8/2018 | 17/6/2026 | A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper implementation of access controls. An attacker… | |
| Modificada | Alta (8.6) | 4.1% | — | Cisco WEB Security Appliance | 15/8/2018 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected software improperly… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco WEB Security Appliance | 1/8/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco WEB Security Appliance | 16/7/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… | |
| Modificada | Alta (7.5) | 3.8% | — | Cisco WEB Security Appliance | 7/6/2018 | 17/6/2026 | A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security protections. The vulnerability is due to a change in the underlying operating system software that is… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco WEB Security Appliance | 18/1/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… | |
| Modificada | Alta (7.2) | 3.2% | — | Trendmicro Interscan WEB Security Virtual Appliance | 22/9/2017 | 17/6/2026 | Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Cloud WEB Security | 19/9/2017 | 17/6/2026 | Cisco Cloud Web Security before 3.0.1.7 allows remote attackers to bypass intended filtering protection mechanisms by leveraging improper handling of HTTP methods, aka Bug ID CSCut69743. | |
| Modificada | Media (4.3) | 1.3% | — | Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance | 17/8/2017 | 17/6/2026 | A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user.… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco WEB Security ApplianceCisco WEB Security Virtual Appliance | 25/7/2017 | 17/6/2026 | A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the administrative management interface of an affected device, aka an Access Control Bypass Vulnerability.… | |
| Modificada | Alta (7.5) | 2.7% | — | Cisco WEB Security ApplianceCisco WEB Security Virtual Appliance | 25/7/2017 | 17/6/2026 | A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected… | |
| Modificada | Media (5.4) | 1.2% | — | Cisco WEB Security ApplianceCisco WEB Security Virtual Appliance | 25/7/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: virtual and hardware versions of… | |
| Modificada | Media (6.7) | 0.82% | — | Cisco WEB Security ApplianceCisco WEB Security Virtual Appliance | 25/7/2017 | 17/6/2026 | A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-level credentials. Affected Products: virtual and hardware… | |
| Modificada | Alta (7.2) | 4.4% | — | Cisco WEB Security Appliance | 25/7/2017 | 17/6/2026 | A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid administrator credentials. Affected Products: Cisco AsyncOS Software 10.0 and later for WSA… | |
| Modificada | Media (6.1) | 0.76% | — | Cisco Cloud WEB Security | 25/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (5.5) | 5.3% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Media (5.5) | 6.9% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Media (5.4) | 2.5% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any… | |
| Modificada | Media (6.5) | 4.1% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure… | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Trendmicro Interscan WEB Security Virtual Appliance | 5/4/2017 | 17/6/2026 | Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and… | |
| Modificada | Media (5.8) | 1.5% | — | Cisco WEB Security Appliance | 17/3/2017 | 17/6/2026 | A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for… | |
| Modificada | Media (5.8) | 1.9% | — | Cisco WEB Security ApplianceCisco Email Security Appliance Firmware | 22/2/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: This vulnerability… |