Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

260 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.9)0.87%—Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector13/4/202117/6/2026
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an attacker to upload a malicious NodeJS file using uploadBackgroud action. An attacker can upload a malicious code or execute any command using a specially crafted packet to…
ModificadaCrítica (10)27%—Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector13/4/202117/6/2026
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper input validation in meta_driver_srv.js class with saveDriverData action using invalidated driverID. An attacker can send specially crafted packets to delete the files on the…
ModificadaCrítica (9.6)1.0%—Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector13/4/202117/6/2026
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input validation at server/maps_srv.js with action removeBackground and server/node_upgrade_srv.js with action removeFirmware. An attacker can send specially crafted packets to…
ModificadaCrítica (10)0.96%—Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector13/4/202117/6/2026
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function under scripts/libs/utils.js. Successful exploitation can allow attackers to…
ModificadaAlta (8.8)0.79%—Eaton Intelligent Power ManagerEaton Intelligent Power Manager Virtual ApplianceEaton Intelligent Power Protector13/4/202117/6/2026
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base.
AnalizadaCrítica (9.8)89%⚠ Explotación activa💥 ExploitSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/202112/8/2026
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
AnalizadaAlta (7.2)17%⚠ Explotación activaSonicwall Email SecuritySonicwall Email Security Appliance 9000 FirmwareSonicwall Email Security Appliance 3300 FirmwareSonicwall Email Security Appliance 4300 Firmware+79/4/20211/10/2026
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
ModificadaMedia (5.5)0.62%—Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+153/3/202117/6/2026
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ModificadaMedia (4.8)0.79%—Cisco WEB Security Virtual Appliance20/1/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based…
ModificadaCrítica (9.8)64%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.
ModificadaCrítica (9.8)2.7%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.
ModificadaAlta (7.5)6.4%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.
ModificadaAlta (7.5)6.0%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.
ModificadaMedia (4.8)1.1%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.
ModificadaAlta (8.8)1.1%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.
ModificadaMedia (4.8)0.72%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product in a manner separate from the similar CVE-2020-8462.
ModificadaAlta (7.2)45%—Trendmicro Interscan WEB Security Virtual Appliance18/11/202017/6/2026
A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
ModificadaAlta (7.2)45%—Trendmicro Interscan WEB Security Virtual Appliance18/11/202017/6/2026
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
ModificadaAlta (8.8)51%—Trendmicro Interscan WEB Security Virtual Appliance18/11/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
ModificadaCrítica (9.8)73%—Trendmicro Interscan WEB Security Virtual Appliance18/11/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
ModificadaAlta (8.8)7.4%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 has updated a specific critical library that may vulnerable to attack.
ModificadaMedia (4.4)1.8%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
ModificadaMedia (5.5)18%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.
ModificadaMedia (5.5)3.5%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's web server and grant access to web resources or parts of local files. An attacker must already have obtained…
ModificadaMedia (4.9)6.5%—Trendmicro Interscan Messaging Security Virtual Appliance9/11/202017/6/2026
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this…