Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Bluecoat SgosBluecoat ProxysgBluecoat Proxysg Sg210-10Bluecoat Proxysg Sg210-25+12 | 26/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Java Management Console in Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Bluecoat SgosBluecoat ProxysgBluecoat Proxysg Sg210-10Bluecoat Proxysg Sg210-25+12 | 26/8/2012 | 16/6/2026 | The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.2.1 allows remote attackers to bypass JavaScript detection via HTML entities. | |
| Modificada | Alta (9.3) | 1.8% | — | Bluecoat SgosBluecoat ProxysgBluecoat Proxysg Sg210-10Bluecoat Proxysg Sg210-25+12 | 26/8/2012 | 16/6/2026 | Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging read-only administrator privileges and establishing an HTTPS session. | |
| Modificada | Media (5.8) | 1.4% | — | Bluecoat Proxysg Va-10Bluecoat Proxysg Va-15Bluecoat Proxysg Va-20Bluecoat Proxysg Va-5+15 | 1/4/2009 | 16/6/2026 | Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web… |