Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.7% | — | Cisco WEB Security Appliance | 3/3/2016 | 17/6/2026 | The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840. | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco WEB Security Appliance | 20/1/2016 | 17/6/2026 | The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848. | |
| Modificada | Media (5) | 1.7% | — | Cisco WEB Security Appliance | 1/12/2015 | 17/6/2026 | The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150. | |
| Modificada | Alta (9) | 1.7% | — | Cisco WEB Security Appliance | 6/11/2015 | 17/6/2026 | The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco WEB Security Appliance | 6/11/2015 | 17/6/2026 | The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple proxy connections, aka… | |
| Modificada | Alta (7.8) | 2.8% | — | Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance | 6/11/2015 | 17/6/2026 | Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco WEB Security Appliance | 6/11/2015 | 17/6/2026 | Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155. | |
| Modificada | Media (4.3) | 0.48% | — | Cisco WEB Security ApplianceCisco Email Security ApplianceCisco Content Security Management Appliance | 29/7/2015 | 17/6/2026 | The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive… | |
| Modificada | Media (4.3) | 1.8% | — | Cisco WEB Security ApplianceCisco Content Security Management Virtual ApplianceCisco Email Security Appliance Firmware | 29/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject arbitrary web script or HTML via an… | |
| Modificada | Media (4.3) | 2.1% | — | Cisco WEB Security Appliance | 20/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web framework on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified HTTP header, aka Bug ID CSCuu24409. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco WEB Security Appliance | 17/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Tracking Report page on Cisco Web Security Appliance (WSA) devices 8.5.0-497 allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCuu16008. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco WEB Security Appliance | 15/4/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213. | |
| Modificada | Alta (7.2) | 0.38% | — | Cisco WEB Security Appliance | 15/4/2015 | 17/6/2026 | Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259. | |
| Modificada | Alta (7.2) | 0.38% | — | Cisco WEB Security Appliance | 11/4/2015 | 17/6/2026 | Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 21/2/2015 | 17/6/2026 | The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639. | |
| Modificada | Media (5) | 1.2% | — | Cisco WEB Security Appliance | 20/2/2015 | 17/6/2026 | The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco WEB Security Appliance | 19/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus40627. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 10/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (4.3) | 0.95% | — | Cisco WEB Security Virtual ApplianceCisco WEB Security Appliance | 2/4/2014 | 17/6/2026 | CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 24/10/2013 | 16/6/2026 | The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP… | |
| Modificada | Media (6.8) | 0.58% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 2/7/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263,… | |
| Modificada | Alta (7.8) | 1.4% | — | Mcafee Email AND WEB Security Appliance | 24/9/2009 | 16/6/2026 | Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However,… |