Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Cisco Email Security Appliance Firmware | 16/7/2015 | 17/6/2026 | Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv14806. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Email Security ApplianceCisco Email Security Appliance Firmware | 10/7/2015 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636. | |
| Modificada | Media (5) | 3.5% | — | Cisco Email Security Appliance | 13/6/2015 | 17/6/2026 | The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Email Security Appliance Firmware | 15/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 21/2/2015 | 17/6/2026 | The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639. | |
| Modificada | Media (5) | 1.2% | — | Cisco Ironport Email Security Appliances | 19/12/2014 | 17/6/2026 | The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 10/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 20/5/2014 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Sonicwall Email Security Appliance | 17/4/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the… | |
| Modificada | Alta (8.5) | 2.7% | — | Cisco Ironport AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 21/3/2014 | 17/6/2026 | The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 24/10/2013 | 16/6/2026 | The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP… | |
| Modificada | Media (6.8) | 0.58% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 2/7/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263,… | |
| Modificada | Alta (9.3) | 5.7% | — | IBM Lotus NotesSymantec Brightmail ApplianceSymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+3 | 1/9/2009 | 16/6/2026 | Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Ironport AsyncosCisco Ironport Email Security Appliances | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter. | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a… | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3)… |