Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.43%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware12/9/201817/6/2026
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
ModificadaMedia (5.3)3.3%—Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+1012/9/201817/6/2026
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
ModificadaMedia (6.7)0.59%—Siemens Simatic Field PG M5 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e FirmwareSiemens Simatic Ipc547e Firmware+1012/9/201817/6/2026
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
ModificadaAlta (7.3)0.46%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware12/9/201817/6/2026
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
ModificadaAlta (8.2)0.48%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services Firmware12/9/201817/6/2026
A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to…
ModificadaMedia (5.9)2.4%—Intel Converged Security Management Engine FirmwareIntel Active Management Technology FirmwareIntel Manageability Engine FirmwareSiemens Simatic Field PG M5 Firmware+1012/9/201817/6/2026
Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
ModificadaAlta (8.2)0.56%—Intel Converged Security Management Engine FirmwareNetapp Element Software Management Node10/7/201817/6/2026
Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access.
ModificadaCrítica (9.8)2.4%—Alienvault Open Source Security Information ManagementAlienvault Unified Security Management14/3/201817/6/2026
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
ModificadaMedia (6.5)1.6%—Cisco Email Security Appliance FirmwareCisco Content Security Management Appliance8/2/201817/6/2026
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of…
ModificadaMedia (5.7)1.9%💥 ExploitAlienvault Unified Security Management18/10/201717/6/2026
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or…
ModificadaMedia (4.3)1.3%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance17/8/201717/6/2026
A vulnerability in SNMP polling for the Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to discover confidential information about the appliances that should be available only to an administrative user.…
ModificadaMedia (6.1)1.2%—Cisco Content Security Management ApplianceCisco Email Security Appliance13/6/201717/6/2026
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device,…
ModificadaCrítica (9.8)15%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
ModificadaAlta (8.8)16%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.
ModificadaAlta (8.4)1.7%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.
ModificadaMedia (4.3)0.58%—Huawei Document Security Management20/3/201717/6/2026
The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissions on the PrintScreen button.
ModificadaCrítica (9.8)6.4%—Alienvault OssimAlienvault Unified Security Management15/3/201717/6/2026
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP…
ModificadaMedia (5.9)1.1%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance14/12/201617/6/2026
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to impersonate the update server. More Information: CSCul88715,…
ModificadaMedia (6.1)0.64%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
ModificadaCrítica (9.8)57%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
ModificadaMedia (6.1)17%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
ModificadaCrítica (9.8)6.9%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
ModificadaMedia (5.9)2.0%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance5/10/201617/6/2026
The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs…
ModificadaMedia (5.4)0.92%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management26/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or HTML via the back parameter to ossim/conf/reload.php.
ModificadaAlta (7.5)95%💥 PoCRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+51/9/201617/6/2026
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated…
Orbitaley — Vulnerabilidades