Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 ExploitSymantec WEB Gateway7/8/201216/6/2026
SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
ModificadaMedia (5)2.8%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.
ModificadaAlta (10)5.4%—Symantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.
ModificadaAlta (7.5)2.5%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.2)59%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.
ModificadaAlta (10)67%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
ModificadaAlta (7.5)1.2%💥 ExploitSymantec WEB Gateway23/7/201216/6/2026
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.
ModificadaAlta (10)64%💥 ExploitSymantec WEB Gateway21/5/201216/6/2026
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors.
ModificadaMedia (6.4)9.3%💥 ExploitSymantec WEB Gateway21/5/201216/6/2026
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors.
ModificadaAlta (10)73%💥 ExploitSymantec WEB Gateway21/5/201216/6/2026
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
ModificadaMedia (4.3)1.6%—Symantec WEB Gateway21/5/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.4%—Mcafee WEB Gateway28/4/201216/6/2026
McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the…
ModificadaAlta (7.5)2.2%—Symantec WEB Gateway11/7/201116/6/2026
SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)2.4%—Symantec WEB Gateway14/1/201116/6/2026
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
ModificadaAlta (9.3)1.9%—Secure Computing Secure WEB GatewaySecure Computing Webwasher12/12/200816/6/2026
Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg…
ModificadaMedia (4.3)1.9%💥 ExploitVtls.web.gateway15/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.
Orbitaley — Vulnerabilidades