Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 119 respecto a la semana anterior
Críticas / altas1267▼ 261 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

2191 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.51%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…
ModificadaMedia (5.4)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaAlta (8.8)0.39%—Silabs Z/ip Gateway SDK21/6/202317/6/2026
Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.
ModificadaAlta (8.8)0.25%—Silabs Z/ip Gateway SDK21/6/202317/6/2026
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
ModificadaMedia (6.8)0.27%—Silabs Z/ip Gateway SDK21/6/202317/6/2026
Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code.
ModificadaBaja (3.5)0.25%—Silabs Z/ip Gateway SDK21/6/202317/6/2026
A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory.
ModificadaAlta (7.5)1.2%—Woocommerce Stripe Payment Gateway14/6/202317/6/2026
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
ModificadaMedia (6.1)0.68%—Vadesecure Secure Gateway9/6/202317/6/2026
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter.
ModificadaMedia (6.1)0.68%—Vadesecure Secure Gateway9/6/202317/6/2026
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory.
ModificadaMedia (6.1)0.88%—Vadesecure Secure Gateway9/6/202317/6/2026
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter.
ModificadaMedia (5.3)0.59%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker…
ModificadaCrítica (9.8)0.71%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly…
ModificadaMedia (6.5)0.34%—Dell Secure Connect Gateway1/6/202317/6/2026
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
ModificadaAlta (8.1)0.47%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
ModificadaMedia (5.4)0.34%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.
ModificadaAlta (7.8)0.19%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
ModificadaCrítica (9.8)1.3%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
AnalizadaCrítica (9.8)88%⚠ Explotación activa💥 ExploitBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/5/202317/6/2026
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete…
ModificadaMedia (6.1)0.38%—Woocommerce Jazzcash Gateway9/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin plugin <= 2.0 versions.
ModificadaCrítica (9.8)0.90%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce8/5/202317/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
ModificadaAlta (7.5)0.56%—Netentsec Application Security Gateway5/5/20239/7/2026
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
ModificadaCrítica (9.8)0.63%—Netentsec Application Security Gateway5/5/20239/7/2026
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
ModificadaAlta (7.5)0.62%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.3)1.2%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which…
ModificadaMedia (6.1)0.39%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+153/5/202317/6/2026
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.