Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Symantec WEB Gateway | 7/8/2012 | 16/6/2026 | SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script. | |
| Modificada | Alta (10) | 5.4% | — | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.2) | 59% | 💥 Exploit | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Symantec WEB Gateway | 23/7/2012 | 16/6/2026 | SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Symantec WEB Gateway | 21/5/2012 | 16/6/2026 | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors. | |
| Modificada | Media (6.4) | 9.3% | 💥 Exploit | Symantec WEB Gateway | 21/5/2012 | 16/6/2026 | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors. | |
| Modificada | Alta (10) | 73% | 💥 Exploit | Symantec WEB Gateway | 21/5/2012 | 16/6/2026 | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data. | |
| Modificada | Media (4.3) | 1.6% | — | Symantec WEB Gateway | 21/5/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Mcafee WEB Gateway | 28/4/2012 | 16/6/2026 | McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the… | |
| Modificada | Alta (7.5) | 2.2% | — | Symantec WEB Gateway | 11/7/2011 | 16/6/2026 | SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Symantec WEB Gateway | 14/1/2011 | 16/6/2026 | SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter. | |
| Modificada | Alta (9.3) | 1.9% | — | Secure Computing Secure WEB GatewaySecure Computing Webwasher | 12/12/2008 | 16/6/2026 | Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Vtls.web.gateway | 15/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter. |