Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.42%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This…
AnalizadaAlta (7.7)0.66%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software14/8/202511/8/2026
A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are…
AnalizadaMedia (5.8)0.71%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software14/8/202518/9/2026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This…
AplazadaCrítica (9.3)4.2%💥 ExploitProofpoint Email Security Virtual ApplianceAI8/8/202516/6/2026
The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation…
AplazadaCrítica (9.3)1.5%💥 ExploitDell Kace K1000 System Management ApplianceAI5/8/202517/6/2026
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are…
AplazadaAlta (8.7)0.39%—Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI14/7/202517/6/2026
The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;…
AplazadaAlta (7.1)0.40%—Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI14/7/202517/6/2026
An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.
AplazadaAlta (8.7)1.1%💥 ExploitAvid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI14/7/202517/6/2026
An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain…
AnalizadaAlta (7.5)0.35%—IBM MQ Appliance11/7/202517/6/2026
An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.
AplazadaCrítica (9.3)0.18%—Quest Kace Systems Management ApplianceAI5/7/202517/6/2026
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.
AnalizadaAlta (7.2)0.65%—Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance27/6/202517/6/2026
Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
AplazadaAlta (7.5)0.91%—Quest Kace Systems Management ApplianceAI24/6/202517/6/2026
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. Attackers can exploit…
AplazadaCrítica (9.6)0.41%—Quest Kace Systems Management ApplianceAI24/6/202517/6/2026
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. While signature validation is implemented, weaknesses in the…
AplazadaAlta (8.8)0.84%—Quest Kace Systems Management ApplianceAI24/6/202517/6/2026
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows authenticated users to bypass TOTP-based 2FA…
AnalizadaCrítica (10)2.5%⚠ Explotación activaQuest Kace Systems Management Appliance24/6/202517/6/2026
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.…
AnalizadaAlta (7.8)0.33%—Ivanti Cloud Services Appliance13/5/202517/6/2026
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (8.6)0.56%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense7/5/202511/8/2026
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…
AplazadaAlta (8.7)0.52%—Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI12/3/202517/6/2026
Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before…
ModificadaAlta (7.5)0.38%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.
ModificadaAlta (7.5)0.59%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.
ModificadaAlta (8.8)0.73%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.
ModificadaCrítica (9.8)0.70%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.
ModificadaCrítica (9.8)0.76%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004.
ModificadaCrítica (9.1)0.32%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.
ModificadaMedia (6.1)0.40%—Printerlogic Vasion PrintPrinterlogic Virtual Appliance5/3/202517/6/2026
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Badge Registration V-2023-005.