Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

180 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
AplazadaCrítica (9.3)0.73%—Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI13/5/202617/6/2026
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user…
AnalizadaBaja (3.8)0.41%—Sonicwall Email Security31/3/202624/7/2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.
AnalizadaBaja (2.7)0.47%—Sonicwall Email Security31/3/202624/7/2026
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.
AnalizadaMedia (4.8)0.29%—Sonicwall Email Security31/3/202624/7/2026
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
AnalizadaMedia (5.3)0.33%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
AnalizadaCrítica (9.8)0.19%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
AnalizadaMedia (6.1)1.9%⚠ Explotación activaLibraesva Email Security Gateway19/9/202517/6/2026
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has…
AplazadaCrítica (9.1)0.56%—Titanhq Spamtitan Email Security GatewayAI21/8/202517/6/2026
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided…
AplazadaCrítica (9.3)4.2%—Proofpoint Email Security Virtual ApplianceAI8/8/202516/6/2026
The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation…
AplazadaMedia (6.1)0.23%—Forcepoint Email SecurityAI24/3/202517/6/2026
Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Security through 8.5.5.
AnalizadaAlta (7.5)0.84%—Cisco Email Security Appliance18/11/202417/6/2026
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability…
AnalizadaMedia (6.1)0.31%—Forcepoint Email Security4/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.
ModificadaMedia (5.5)0.20%—Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+416/7/202417/6/2026
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met.
AplazadaMedia (4.9)0.90%—Sonicwall Email Security ApplianceAI14/3/202417/6/2026
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system.
ModificadaAlta (7.8)0.55%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+515/2/202417/6/2026
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.
ModificadaMedia (5.5)0.28%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+231/1/202417/6/2026
Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.
ModificadaCrítica (9.8)0.71%—Cisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware10/1/202417/6/2026
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
ModificadaCrítica (9.8)45%—Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/12/202317/6/2026
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
ModificadaAlta (8.6)0.38%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+521/12/202317/6/2026
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted.
ModificadaAlta (7.8)0.18%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+414/8/202317/6/2026
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
ModificadaCrítica (9.8)0.51%—Forcepoint Email SecurityForcepoint WEB Security15/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
AnalizadaCrítica (9.8)88%⚠ Explotación activaBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/5/202317/6/2026
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete…
ModificadaMedia (6.7)0.45%—Cisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…