Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaMedia (6.1)0.51%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…
ModificadaMedia (5.4)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaMedia (5.3)0.93%—Cisco WEB Security Appliance6/4/202217/6/2026
A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling…
ModificadaAlta (8.6)1.7%—Cisco Ironport WEB Security ApplianceCisco Secure Firewall Management CenterCisco Firepower Management Center Virtual Appliance Firmware18/8/202117/6/2026
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised…
ModificadaAlta (8.8)1.9%—Cisco WEB Security ApplianceCisco Asyncos8/7/202117/6/2026
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An…
ModificadaAlta (7.4)0.67%—Cisco Email Security ApplianceCisco AsyncosCisco WEB Security Appliance16/6/202117/6/2026
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This…
ModificadaMedia (6.5)1.0%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security ApplianceCisco Ironport WEB Security Appliance6/5/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The…
ModificadaMedia (6.1)0.70%—Cisco WEB Security Appliance6/5/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of…
ModificadaMedia (5.3)1.1%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance20/1/202117/6/2026
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain…
ModificadaMedia (4.7)0.93%—Cisco Content Security Management ApplianceCisco WEB Security Appliance23/9/202017/6/2026
A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The vulnerability is due to insufficient validation of user…
ModificadaMedia (6.1)0.80%—Cisco WEB Security Appliance23/9/202017/6/2026
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by…
ModificadaMedia (5.3)1.3%—Cisco Cloud Email SecurityCisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance4/3/202017/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial…
ModificadaAlta (7.4)0.66%—Cisco Ironport WEB Security Appliance15/1/202016/6/2026
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks
ModificadaMedia (5.9)0.58%—Cisco Ironport WEB Security Appliance15/1/202016/6/2026
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
ModificadaMedia (6.4)0.26%—Cisco Ironport WEB Security Appliance15/1/202016/6/2026
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks
ModificadaAlta (8.8)0.98%—Cisco AsyncosCisco WEB Security Appliance26/11/201917/6/2026
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web…
ModificadaAlta (8.6)1.3%—Cisco AsyncosCisco WEB Security Appliance4/7/201917/6/2026
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this…
ModificadaMedia (6.5)1.5%—Cisco AsyncosCisco WEB Security Appliance4/7/201917/6/2026
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in…
ModificadaAlta (7.5)1.8%—Cisco WEB Security Appliance3/5/201917/6/2026
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of HTTP and HTTPS requests. An attacker could…
ModificadaAlta (7.8)0.64%—Cisco WEB Security Appliance3/5/201917/6/2026
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The vulnerability is due to insufficient validation of user-supplied input on the web and command-line interface. An…
ModificadaMedia (5.8)1.6%—Cisco WEB Security Appliance8/2/201917/6/2026
A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of…
ModificadaMedia (6.7)0.44%—Cisco WEB Security Appliance15/8/201817/6/2026
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper implementation of access controls. An attacker…
ModificadaAlta (8.6)4.1%—Cisco WEB Security Appliance15/8/201817/6/2026
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected software improperly…