Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

183 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.7%—Mcafee Email Gateway13/12/201317/6/2026
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) event_id, (3) reason, (4) events_order, (5) emailstatus_order, or (6) emailstatus_col JSON keys.
ModificadaAlta (8.5)2.5%—Mcafee Email Gateway2/11/201317/6/2026
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
ModificadaAlta (7.1)1.4%—Moxa Oncell Gateway FirmwareMoxa Oncell Gateway G3111Moxa Oncell Gateway G3151Moxa Oncell Gateway G3211+19/8/201316/6/2026
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.
ModificadaBaja (3.5)0.84%—Symantec Brightmail Gateway9/5/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in administrative-interface pages in the management console in Symantec Brightmail Gateway 9.5.x allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.1%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard.
ModificadaMedia (4.3)2.6%—Mcafee Email Gateway22/8/201216/6/2026
Directory traversal vulnerability in McAfee Email Gateway (MEG) 7.0.0 and 7.0.1 allows remote authenticated users to bypass intended access restrictions and download arbitrary files via a crafted URL.
ModificadaAlta (7.5)2.5%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors.
ModificadaBaja (3.5)0.92%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
ModificadaMedia (4)0.94%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL.
ModificadaBaja (3.5)0.85%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not properly encrypt system-backup data, which makes it easier for remote authenticated users to obtain sensitive information by reading a backup file, as demonstrated by obtaining…
ModificadaMedia (4)0.94%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
ModificadaMedia (4.9)0.85%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to reset the passwords of arbitrary administrative accounts via unspecified vectors.
ModificadaMedia (6.8)1.2%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session…
ModificadaMedia (4.3)1.4%—Mcafee Email AND WEB SecurityMcafee Email Gateway22/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management…
ModificadaMedia (6.5)2.3%—Mcafee Email GatewayMcafee Secure Mail28/5/201016/6/2026
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.
ModificadaAlta (10)3.7%—IBM Lotus NotesSymantec Brightmail GatewaySymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+25/3/201016/6/2026
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a…
ModificadaMedia (5)4.2%💥 ExploitCisco ACE WEB Application FirewallCisco ACE XML Gateway29/9/200916/6/2026
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client…
ModificadaAlta (7.6)2.8%—Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+930/4/200916/6/2026
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in…
ModificadaAlta (9)2.2%—Symantec Brightmail Gateway Appliance24/4/200916/6/2026
Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console…
ModificadaMedia (4.3)1.3%—Symantec Brightmail Gateway Appliance24/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)7.2%💥 ExploitSUN Java System Delegated Administrator23/4/200916/6/2026
CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.
ModificadaMedia (5)2.9%—Delegate27/4/200616/6/2026
Multiple unspecified vulnerabilities in DeleGate 9.x before 9.0.6 and 8.x before 8.11.6 allow remote attackers to cause a denial of service via crafted DNS responses messages that cause (1) a buffer over-read or (2) infinite recursion, which can trigger a segmentation fault or invalid memory access, as demonstrated by…
ModificadaMedia (5)2.7%—DelegateETL Delegate31/12/200516/6/2026
The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.
ModificadaAlta (7.5)2.6%—SUN Java Communications Services Delegated Administrator7/12/200516/6/2026
Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.
ModificadaAlta (7.5)2.4%—Delegate2/5/200516/6/2026
Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."