Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)0.21%—Huawei Document Security Management8/1/201617/6/2026
Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file.
ModificadaAlta (7.8)2.8%—Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance6/11/201517/6/2026
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before…
ModificadaMedia (5)2.2%—Cisco Content Security Management Appliance14/9/201517/6/2026
Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.
ModificadaMedia (5.5)1.7%—Cisco Content Security Management Appliance19/8/201517/6/2026
Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder by visiting a spam-notification URL, aka Bug ID CSCuv65894.
ModificadaMedia (4.3)0.48%—Cisco WEB Security ApplianceCisco Email Security ApplianceCisco Content Security Management Appliance29/7/201517/6/2026
The LDAP implementation on the Cisco Web Security Appliance (WSA) 8.5.0-000, Email Security Appliance (ESA) 8.5.7-042, and Content Security Management Appliance (SMA) 8.3.6-048 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive…
ModificadaMedia (4.3)1.8%—Cisco WEB Security ApplianceCisco Content Security Management Virtual ApplianceCisco Email Security Appliance Firmware29/7/201517/6/2026
Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote attackers to inject arbitrary web script or HTML via an…
ModificadaMedia (4.3)2.2%—Cisco Content Security Management Virtual ApplianceCisco Email Security Virtual ApplianceCisco WEB Security Virtual Appliance26/6/201517/6/2026
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to…
ModificadaMedia (5)3.3%—Cisco Content Security Management Virtual ApplianceCisco Email Security Virtual ApplianceCisco WEB Security Virtual Appliance26/6/201517/6/2026
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easier for remote…
ModificadaAlta (9.3)2.4%—Alienvault Unified Security Management1/5/201517/6/2026
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).
ModificadaAlta (7.5)8.6%—HP Tippingpoint Security Management SystemHP Tippingpoint Virtual Security Management System27/4/201517/6/2026
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2)…
ModificadaMedia (4.3)2.2%—Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware21/2/201517/6/2026
The web framework in Cisco AsyncOS on Email Security Appliance (ESA), Content Security Management Appliance (SMA), and Web Security Appliance (WSA) devices allows remote attackers to trigger redirects via a crafted HTTP header, aka Bug IDs CSCur44412, CSCur44415, CSCur89630, CSCur89636, CSCur89633, and CSCur89639.
ModificadaMedia (4.3)2.4%—Cisco Ironport AsyncosCisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware10/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or…
ModificadaMedia (4.3)1.2%—Cisco AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware20/5/201417/6/2026
Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085.
ModificadaAlta (8.5)2.7%—Cisco Ironport AsyncosCisco Content Security Management ApplianceCisco Email Security Appliance Firmware21/3/201417/6/2026
The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root…
ModificadaAlta (7.5)5.5%—HP Security Management System6/3/201417/6/2026
Unspecified vulnerability in HP Security Management System 3.3.0, 3.5.0 before patch 1, and 3.6.0 before patch 2 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.8)1.3%—Cisco WEB Security ApplianceCisco Content Security Management ApplianceCisco Email Security Appliance Firmware24/10/201316/6/2026
The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of service (management GUI outage) via multiple TCP…
ModificadaMedia (6.8)0.58%—Cisco Content Security Management ApplianceCisco WEB Security ApplianceCisco Email Security Appliance Firmware2/7/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263,…
ModificadaMedia (4.3)0.93%—Cisco Content Security Management Appliance26/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.
ModificadaMedia (5)2.8%💥 ExploitHirschelectronics Velocity Security Management System26/8/200916/6/2026
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaAlta (7.2)0.37%—Novell Zenworks Endpoint Security Management9/1/200816/6/2026
STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the…
ModificadaMedia (4.6)0.64%—Mcafee Intrushield Security Management System11/7/200516/6/2026
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to…
ModificadaAlta (7.5)1.6%—Mcafee Intrushield Security Management System11/7/200516/6/2026
McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.
ModificadaBaja (1.9)0.54%—Mcafee Intrushield Security Management System11/7/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.