Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.30%—Cisco AsyncosAICisco Secure WEB ApplianceAI15/4/202617/6/2026
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An…
AplazadaMedia (4)0.16%—Cisco AsyncosAICisco Secure WEB ApplianceAI4/2/202617/6/2026
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded.
AplazadaCrítica (10)1.4%—ApacheAISophos WEB ApplianceAI30/8/20251/10/2026
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user.…
AplazadaAlta (8.7)0.78%—Imperio Software Contentkeeper WEB ApplianceAI20/8/20251/10/2026
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters,…
AplazadaMedia (4.3)0.34%—Cisco Secure Email AND WEB ManagerAICisco Secure Email GatewayAICisco Secure WEB ApplianceAI5/2/202517/6/2026
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (4.8)0.58%—Sophos WEB Appliance30/6/202317/6/2026
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
AnalizadaCrítica (9.8)100%⚠ Explotación activaSophos WEB Appliance4/4/202317/6/2026
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
ModificadaAlta (7.2)1.8%—Sophos WEB Appliance4/4/202317/6/2026
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
ModificadaMedia (5.4)0.57%—Sophos WEB Appliance4/4/202317/6/2026
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
ModificadaMedia (6.1)1.2%—IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+229/8/201717/6/2026
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
ModificadaMedia (6.1)1.2%—Sophos WEB Appliance9/6/201717/6/2026
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
ModificadaAlta (8.1)7.5%—Sophos WEB Appliance30/3/201717/6/2026
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
ModificadaMedia (4.7)2.5%—Sophos WEB Appliance30/3/201717/6/2026
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
ModificadaAlta (7.2)3.2%—Sophos WEB Appliance30/3/201717/6/2026
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314.
ModificadaCrítica (9.8)17%—Sophos WEB Appliance30/3/201717/6/2026
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.
ModificadaAlta (7.2)25%—Sophos WEB Appliance28/1/201717/6/2026
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing…
ModificadaAlta (7.2)19%—Sophos WEB Appliance28/1/201717/6/2026
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device.…
ModificadaMedia (4.3)1.4%—IBM Security Access Manager FOR Mobile 8.0 FirmwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB Appliance+13/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML…
ModificadaAlta (10)2.8%—IBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR Mobile 8.0 Firmware+13/10/201417/6/2026
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.
ModificadaAlta (7.1)1.5%—IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB 7.0 Firmware3/10/201417/6/2026
The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors.
ModificadaAlta (10)4.2%—IBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB Appliance21/6/201417/6/2026
Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (8)1.4%—IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB Software+121/6/201417/6/2026
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.
ModificadaBaja (3.3)0.36%—IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB Appliance21/6/201417/6/2026
The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that…
ModificadaAlta (7.1)3.1%—IBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB Appliance8/5/201417/6/2026
The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.