Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.67% | — | Cisco Email Security ApplianceCisco AsyncosCisco WEB Security Appliance | 16/6/2021 | 17/6/2026 | A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This… | |
| Modificada | Crítica (9.8) | 2.5% | — | Async-git Project Async-git | 18/2/2021 | 17/6/2026 | The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb') | |
| Modificada | Crítica (9.8) | 5.3% | — | Async-git Project Async-git | 26/1/2021 | 17/6/2026 | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. | |
| Modificada | Media (6.1) | 0.81% | — | Rust-lang Async-h1 | 26/1/2021 | 17/6/2026 | An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy. | |
| Modificada | Alta (7.5) | 1.0% | — | Rust-lang Async-h1 | 21/12/2020 | 17/6/2026 | async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async-h1 behind a reverse proxy, including all such Tide applications. If the server does not read the body of a request… | |
| Modificada | Alta (7.8) | 0.80% | — | Cisco Asyncos | 18/11/2020 | 17/6/2026 | A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Media (5.8) | 1.0% | — | Cisco Asyncos | 8/10/2020 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could… | |
| Modificada | Media (5.3) | 1.9% | — | Cisco Content Security Management ApplianceCisco AsyncosCisco Email Security Appliance | 23/9/2020 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices,… | |
| Modificada | Alta (8.6) | 1.9% | — | Cisco Email Security ApplianceCisco Asyncos | 23/9/2020 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due… | |
| Modificada | Media (6.5) | 0.88% | — | Cisco Asyncos | 4/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Asyncos | 4/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based… | |
| Modificada | Crítica (9.8) | 2.4% | — | Magic AsyncpgDebian Linux | 12/8/2020 | 17/6/2026 | asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder. | |
| Modificada | Media (5.8) | 1.4% | — | Cisco Asyncos | 18/6/2020 | 17/6/2026 | A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could… | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Aasync | 29/4/2020 | 17/6/2026 | AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco AsyncosCisco WEB Security Appliance | 26/11/2019 | 17/6/2026 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco AsyncosCisco WEB Security Appliance | 4/7/2019 | 17/6/2026 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in… | |
| Modificada | Alta (8.6) | 2.5% | — | Cisco Asyncos | 10/1/2019 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due… | |
| Modificada | Crítica (9.8) | 1.7% | — | Asyncssh Project Asyncssh | 12/3/2018 | 17/6/2026 | The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step. | |
| Modificada | Media (5.6) | 1.8% | — | Cisco Asyncos | 8/3/2018 | 17/6/2026 | A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability is due to incorrect FTP user credential validation. An… | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Asyncos | 18/1/2018 | 17/6/2026 | A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Asyncos | 30/11/2017 | 17/6/2026 | A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a malformed MIME header… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Asyncos | 16/11/2017 | 17/6/2026 | A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Asyncos | 21/9/2017 | 17/6/2026 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Asyncos | 7/9/2017 | 17/6/2026 | A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated, remote attacker to cause an email attachment containing malware to be delivered to the end user. The vulnerability is due… |