Vulnerabilities

Summary — last 7 days

New vulnerabilities2,633▼ 304 vs. last week
Critical / high1,352▲ 80 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)58▼ 469 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.4)0.88%—Clavister Coreplus7/16/20076/16/2026
The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates.
ModifiedHigh (10)2.3%—Clavister Coreplus7/16/20076/16/2026
The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists.
ModifiedMedium (5)1.9%—Clavister Coreplus7/16/20076/16/2026
The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.