Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.26% | — | Symantec Encryption DesktopSymantec PGP Desktop | 18/2/2013 | 16/6/2026 | Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a crafted application. | |
| Modificada | Media (6.9) | 0.49% | — | Sophos Free EncryptionSophos Safeguard Privatecrypto | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this… | |
| Modificada | Media (6.9) | 0.36% | — | Nchsoftware MEO Encryption Software | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .meo or .cry file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.34% | — | Sophos Safeguard Enterprise Device EncryptionSophos Safeguard Easy Device Encryption ClientSophos Disk Encryption | 24/8/2012 | 16/6/2026 | Sophos SafeGuard Enterprise Device Encryption 5.x through 5.50.8.13, Sophos SafeGuard Easy Device Encryption Client 5.50.x, and Sophos Disk Encryption 5.50.x have a delay before removal of (1) out-of-date credentials and (2) invalid credentials, which allows physically proximate attackers to defeat the full-disk… | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Ironport Encryption Appliance | 13/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitrary web script or HTML via the header parameter to the default URI under admin/, aka bug ID 72410. | |
| Modificada | Media (5) | 0.90% | — | Johan Lindskog AES Encryption Module | 7/2/2011 | 16/6/2026 | The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user. | |
| Modificada | Alta (10) | 4.4% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka IronPort Bug 65923. | |
| Modificada | Alta (7.8) | 0.88% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65922. | |
| Modificada | Alta (7.8) | 0.88% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65921. | |
| Modificada | Baja (2.1) | 0.20% | — | Mcafee Safeboot Device Encryption | 21/8/2009 | 16/6/2026 | McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. | |
| Modificada | Media (6.8) | 0.55% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers… | |
| Modificada | Media (6.8) | 0.45% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers… | |
| Modificada | Media (4.3) | 0.79% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified… | |
| Modificada | Media (4.3) | 0.79% | — | Cisco Ironport Encryption ApplianceCisco Ironport Postx | 16/1/2009 | 16/6/2026 | PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to… | |
| Modificada | Baja (2.1) | 0.24% | — | Fujitsu FenceFujitsu Systemwalker Desktop Encryption | 19/3/2007 | 16/6/2026 | Fujitsu FENCE-Pro before V5L01, and Systemwalker Desktop Encryption V12.0L10, V12.0L10A, V12.0L10B, V12.0L20 and V13.0.0 allows local users to obtain sensitive information by extracting the decoding password from certain "self-decoding" file types. | |
| Modificada | Media (5) | 1.5% | — | Gaim-encryption | 31/12/2005 | 16/6/2026 | Gaim-Encryption 2.38-1 on Debian Linux allows remote attackers to cause a denial of service (crash) via a crafted message from an ICQ buddy, possibly involving the GE_received_key function in keys.c. | |
| Modificada | Media (5) | 1.0% | — | Gaim-encryption | 5/5/2003 | 16/6/2026 | decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte. |