Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.30% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 15/4/2026 | 17/6/2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An… | |
| Aplazada | Media (4) | 0.16% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 4/2/2026 | 17/6/2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. | |
| Aplazada | Crítica (10) | 1.4% | — | ApacheAISophos WEB ApplianceAI | 30/8/2025 | 1/10/2026 | ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user.… | |
| Aplazada | Alta (8.7) | 0.78% | — | Imperio Software Contentkeeper WEB ApplianceAI | 20/8/2025 | 1/10/2026 | ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters,… | |
| Aplazada | Media (4.3) | 0.34% | — | Cisco Secure Email AND WEB ManagerAICisco Secure Email GatewayAICisco Secure WEB ApplianceAI | 5/2/2025 | 17/6/2026 | A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.8) | 0.58% | — | Sophos WEB Appliance | 30/6/2023 | 17/6/2026 | Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Sophos WEB Appliance | 4/4/2023 | 17/6/2026 | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. | |
| Modificada | Alta (7.2) | 1.8% | — | Sophos WEB Appliance | 4/4/2023 | 17/6/2026 | A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.57% | — | Sophos WEB Appliance | 4/4/2023 | 17/6/2026 | A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA. | |
| Modificada | Media (6.1) | 1.2% | — | IBM Tivoli Access Manager FOR E-businessIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB+2 | 29/8/2017 | 17/6/2026 | IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687. | |
| Modificada | Media (6.1) | 1.2% | — | Sophos WEB Appliance | 9/6/2017 | 17/6/2026 | The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342. | |
| Modificada | Alta (8.1) | 7.5% | — | Sophos WEB Appliance | 30/3/2017 | 17/6/2026 | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | |
| Modificada | Media (4.7) | 2.5% | — | Sophos WEB Appliance | 30/3/2017 | 17/6/2026 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. | |
| Modificada | Alta (7.2) | 3.2% | — | Sophos WEB Appliance | 30/3/2017 | 17/6/2026 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314. | |
| Modificada | Crítica (9.8) | 17% | — | Sophos WEB Appliance | 30/3/2017 | 17/6/2026 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304. | |
| Modificada | Alta (7.2) | 25% | — | Sophos WEB Appliance | 28/1/2017 | 17/6/2026 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing… | |
| Modificada | Alta (7.2) | 19% | — | Sophos WEB Appliance | 28/1/2017 | 17/6/2026 | The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device.… | |
| Modificada | Media (4.3) | 1.4% | — | IBM Security Access Manager FOR Mobile 8.0 FirmwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB Appliance+1 | 3/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Alta (10) | 2.8% | — | IBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR Mobile 8.0 Firmware+1 | 3/10/2014 | 17/6/2026 | The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.5% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR WEB 7.0 Firmware | 3/10/2014 | 17/6/2026 | The WebSEAL component in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, when e-community SSO is enabled, allows remote attackers to cause a denial of service (component hang) via unspecified vectors. | |
| Modificada | Alta (10) | 4.2% | — | IBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB Appliance | 21/6/2014 | 17/6/2026 | Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (8) | 1.4% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB ApplianceIBM Security Access Manager FOR Mobile SoftwareIBM Security Access Manager FOR WEB Software+1 | 21/6/2014 | 17/6/2026 | The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials. | |
| Modificada | Baja (3.3) | 0.36% | — | IBM Security Access Manager FOR WEB 8.0 FirmwareIBM Security Access Manager FOR WEB Appliance | 21/6/2014 | 17/6/2026 | The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that… | |
| Modificada | Alta (7.1) | 3.1% | — | IBM Security Access Manager FOR WEB SoftwareIBM Security Access Manager FOR WEB Appliance | 8/5/2014 | 17/6/2026 | The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages. |