Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.67% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators… | |
| Modificada | Alta (7.5) | 2.4% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to execute arbitrary commands via unknown vectors, related to a "command injection" issue. | |
| Modificada | Alta (7.5) | 1.3% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | SQL injection vulnerability in an unspecified function in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 1.9% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | Directory traversal vulnerability in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Proofpoint Messaging Security GatewayProofpoint Protection Server | 5/5/2011 | 16/6/2026 | The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | IBM Websphere Datapower XML Accelerator Xa35IBM Websphere Datapower XML Security Gateway Xs40IBM Websphere Datapower Datapower Integration Appliance Xi50IBM Websphere Datapower B2B Appliance Xb60+1 | 29/4/2010 | 16/6/2026 | The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP… | |
| Modificada | Alta (7.6) | 5.5% | — | F-secure Anti-virusF-secure Anti-virus FOR Citrix ServersF-secure Anti-virus FOR Microsoft ExchangeF-secure Anti-virus FOR Mimesweeper+13 | 6/2/2009 | 16/6/2026 | Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer… | |
| Modificada | Alta (7.8) | 3.5% | 💥 Exploit | IBM Websphere Datapower XML Security Gateway Xs40 | 15/1/2009 | 16/6/2026 | The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data. | |
| Modificada | Media (4.3) | 1.5% | — | Bluecoat Security Gateway OS | 8/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.8) | 2.6% | — | Astaro Security Gateway | 8/8/2007 | 16/6/2026 | Unspecified vulnerability in pfilter-reporter.pl in Astaro Security Gateway (ASG) 7 allows remote attackers to cause a denial of service (CPU consumption) via certain network traffic, as demonstrated by P2P and iTunes applications that download large amounts of data. | |
| Modificada | Media (5) | 1.5% | — | Astaro Security Gateway | 8/8/2007 | 16/6/2026 | The pop3 Proxy in Astaro Security Gateway (ASG) 7 does not perform virus scanning of attachments that exceed the maximum attachment size, and passes these attachments, which allows remote attackers to bypass this scanning via a large attachment. | |
| Modificada | Alta (7.8) | 2.9% | — | Astaro Security Gateway | 18/6/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning; (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web… | |
| Modificada | Alta (7.5) | 2.8% | — | Clavister FirewallClavister Security Gateway | 30/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear… | |
| Modificada | Alta (7.5) | 0.86% | — | Broadcom Bluecoat Security Gateway | 31/12/2004 | 16/6/2026 | The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates. |