Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.9% | — | Cisco Email Security Appliance | 6/11/2015 | 17/6/2026 | Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering,… | |
| Modificada | Media (6.8) | 1.7% | — | Cisco Email Security ApplianceCisco Email Security Appliance Firmware | 2/10/2015 | 17/6/2026 | Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211. | |
| Modificada | Media (6.4) | 1.4% | — | Cisco Email Security Appliance | 14/9/2015 | 17/6/2026 | Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497. | |
| Modificada | Media (4.3) | 0.48% | — | Cisco WEB Security ApplianceCisco Email Security ApplianceCisco Content Security Management Appliance | 29/7/2015 | 17/6/2026 | The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive… | |
| Modificada | Media (4.3) | 1.8% | — | Cisco WEB Security ApplianceCisco Content Security Management Virtual ApplianceCisco Email Security Appliance Firmware | 29/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject arbitrary web script or HTML via an… | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Email Security Appliance Firmware | 16/7/2015 | 17/6/2026 | Cisco Email Security Appliance (ESA) devices with software 8.5.6-106 and 9.5.0-201 allow remote attackers to cause a denial of service (per-domain e-mail reception outage) by placing malformed DMARC policy data in DNS TXT records for a domain, aka Bug ID CSCuv14806. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Email Security ApplianceCisco Email Security Appliance Firmware | 10/7/2015 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Content Security Management Virtual ApplianceCisco Email Security Virtual ApplianceCisco WEB Security Virtual Appliance | 26/6/2015 | 17/6/2026 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to… | |
| Modificada | Media (5) | 3.3% | — | Cisco Content Security Management Virtual ApplianceCisco Email Security Virtual ApplianceCisco WEB Security Virtual Appliance | 26/6/2015 | 17/6/2026 | The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easier for remote… | |
| Modificada | Media (5) | 3.5% | — | Cisco Email Security Appliance | 13/6/2015 | 17/6/2026 | The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF record, aka Bug IDs CSCuu35853 and CSCuu37733. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Email Security Appliance Firmware | 15/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 21/2/2015 | 17/6/2026 | The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639. | |
| Modificada | Media (5) | 1.2% | — | Cisco Ironport Email Security Appliances | 19/12/2014 | 17/6/2026 | The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in e-mail messages, aka Bug ID CSCzv93864. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 10/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 20/5/2014 | 17/6/2026 | Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Sonicwall Email Security Appliance | 17/4/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the… | |
| Modificada | Alta (8.5) | 2.7% | — | Cisco Ironport AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 21/3/2014 | 17/6/2026 | The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware | 24/10/2013 | 16/6/2026 | The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP… | |
| Modificada | Media (6.8) | 0.58% | — | Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware | 2/7/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263,… | |
| Modificada | Media (5) | 1.4% | — | Websense Email Security | 26/8/2012 | 16/6/2026 | The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to bypass intended access restrictions and send e-mail messages via an SMTP session. | |
| Modificada | Media (4.3) | 1.1% | — | Websense Email Security | 26/8/2012 | 16/6/2026 | The Rules Service in Websense Email Security before 7.1 allows remote attackers to cause a denial of service (service crash) via an attachment with a crafted size. | |
| Modificada | Media (5) | 1.4% | — | Websense Email Security | 23/8/2012 | 16/6/2026 | The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry key, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force… | |
| Modificada | Media (5) | 1.2% | — | Websense Email Security | 23/8/2012 | 16/6/2026 | The Personal Email Manager component in Websense Email Security before 7.2 allows remote attackers to obtain potentially sensitive information from the JBoss status page via an unspecified query. | |
| Modificada | Media (5) | 1.2% | — | Websense Email Security | 23/8/2012 | 16/6/2026 | Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword in the SMTP session. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Websense Email SecurityWebsense Personal Email Manager | 22/10/2009 | 16/6/2026 | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response. |