Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.0%—Citrix Secure Mail6/1/202117/6/2026
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the…
ModificadaMedia (6.5)2.1%—Citrix Secure Mail6/1/202117/6/2026
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary…
ModificadaMedia (6.1)0.85%—Kaspersky Secure Mail Gateway6/2/201817/6/2026
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
ModificadaAlta (7.8)0.48%—Kaspersky Secure Mail Gateway6/2/201817/6/2026
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
ModificadaCrítica (9.8)6.6%—Kaspersky Secure Mail Gateway6/2/201817/6/2026
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
ModificadaAlta (8.8)0.64%—Kaspersky Secure Mail Gateway6/2/201817/6/2026
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
ModificadaMedia (4.3)1.0%—Aker Secure Mail Gateway11/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.
ModificadaMedia (6.5)2.3%—Mcafee Email GatewayMcafee Secure Mail28/5/201016/6/2026
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.