Vulnerabilities

Summary — last 7 days

New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (5.3)0.30%—Cisco AsyncosAICisco Secure WEB ApplianceAI4/15/20266/17/2026
A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An…
DeferredMedium (4)0.15%—Cisco AsyncosAICisco Secure WEB ApplianceAI2/4/20266/17/2026
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded.
DeferredMedium (4.3)0.34%—Cisco Secure Email AND WEB ManagerAICisco Secure Email GatewayAICisco Secure WEB ApplianceAI2/5/20256/17/2026
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists…
AnalyzedHigh (7.5)100%⚠ Active exploitationSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/20238/11/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.