Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.51%—Asylumdigital AGE GateAI9/4/202517/6/2026
Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Age Gate: from n/a through <= 3.5.4.
AplazadaCrítica (9.8)4.9%—Asylumdigital AGE GateAI20/3/202517/6/2026
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files on the server, allowing the execution of code in those files. This can be…
ModificadaMedia (6.1)0.80%—Asylumdigital AGE Gate15/6/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress.
ModificadaCrítica (9.1)1.1%—Oracle Cloud Infrastructure Storage Gateway22/4/202117/6/2026
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud…
ModificadaCrítica (9.1)1.1%—Oracle Cloud Infrastructure Storage Gateway22/4/202117/6/2026
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud…
ModificadaCrítica (9.1)1.1%—Oracle Cloud Infrastructure Storage Gateway22/4/202117/6/2026
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cloud…
ModificadaCrítica (10)1.9%—Oracle Cloud Infrastructure Storage Gateway22/4/202117/6/2026
Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 1.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud…
ModificadaCrítica (9.8)4.5%—IBM IOT MessagesightIBM Watson IOT Platform - Message Gateway28/1/202017/6/2026
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute…
ModificadaCrítica (9.8)2.3%—Symantec Message Gateway11/7/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaAlta (8.8)2.1%—Symantec Message Gateway11/8/201717/6/2026
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF…
AnalizadaAlta (8.8)36%⚠ Explotación activaSymantec Message Gateway11/8/201717/6/2026
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the…
ModificadaAlta (8.4)18%—Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+1430/6/201617/6/2026
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before…
ModificadaCrítica (9.8)25%—Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+1430/6/201617/6/2026
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec…
ModificadaAlta (8.4)18%—Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+1430/6/201617/6/2026
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before…
ModificadaAlta (7.8)53%—Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+1430/6/201617/6/2026
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before…
ModificadaAlta (7.3)11%—Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+1430/6/201617/6/2026
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaAlta (7.3)21%—Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+1430/6/201617/6/2026
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaAlta (8.4)18%—Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+1430/6/201617/6/2026
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before…