Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2776▲ 17 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

5112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Genetec Security Center5/4/202317/6/2026
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules) allows Reflected…
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_form.mhtml modules) allows Reflected…
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules)…
ModificadaMedia (4.3)0.80%—Gitlab Dynamic Application Security Testing Analyzer27/3/202317/6/2026
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence.
ModificadaAlta (7.5)0.72%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat Defense23/3/202311/8/2026
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote…
ModificadaMedia (5.9)0.68%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco IOSCisco IOS XE23/3/202311/8/2026
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.…
ModificadaAlta (7.2)0.74%—IBM Qradar Security Information AND Event Manager22/3/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.
ModificadaAlta (8.8)0.40%—IBM Security KEY Lifecycle Manager22/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630.
ModificadaMedia (5.3)0.94%—IBM Security KEY Lifecycle Manager22/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606.
ModificadaCrítica (9.8)0.97%—IBM Security KEY Lifecycle Manager21/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597.
ModificadaAlta (7.5)0.67%—IBM Security KEY Lifecycle Manager21/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629.
ModificadaMedia (5.5)0.17%—IBM Security KEY Lifecycle Manager21/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601.
ModificadaMedia (5.3)0.68%—IBM Security KEY Lifecycle Manager21/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618.
ModificadaMedia (4.3)0.48%—IBM Security KEY Lifecycle Manager21/3/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602.
ModificadaMedia (6.5)0.75%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
ModificadaMedia (6.1)0.54%—Gitlab Dynamic Application Security Testing Analyzer9/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
ModificadaMedia (6.5)0.80%—Gitlab Dynamic Application Security Testing Analyzer8/3/202317/6/2026
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
ModificadaMedia (5.3)0.33%—Amazon OpensearchAmazon Opensearch Security2/3/202317/6/2026
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity…
ModificadaMedia (6.7)0.45%💥 PoCCisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaAlta (7.2)1.3%💥 PoCCisco Email Security ApplianceCisco Secure Email AND WEB Manager1/3/202317/6/2026
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user…
ModificadaAlta (7.5)0.39%—IBM Qradar Security Information AND Event Manager17/2/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.
ModificadaMedia (6.5)0.42%—IBM Security Verify AccessIBM Security Verify Access Docker17/2/202317/6/2026
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0 y 10.0.4.0 es vulnerable a la inyección de encabezados HTTP, causada por una validación incorrecta de la entrada por parte de los encabezados HOST. Esto podría permitir a un atacante realizar varios ataques contra el sistema vulnerable, incluyendo…