Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Barracuda WEB Filter | 25/5/2015 | 17/6/2026 | Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust… | |
| Modificada | Media (4.3) | 0.76% | — | Barracuda WEB Filter | 25/5/2015 | 17/6/2026 | Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.5% | — | Websense Triton AP WEBWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+1 | 25/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML… | |
| Modificada | Media (5.4) | 0.27% | — | Cloudacl Safe Browser - THE WEB Filter | 11/10/2014 | 17/6/2026 | The Safe Browser - The Web Filter (aka com.cloudacl) application 1.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 1.3% | — | Websense Triton Unified Security CenterWebsense Triton WEB FilterWebsense Triton WEB SecurityWebsense Triton WEB Security Gateway+1 | 12/4/2014 | 17/6/2026 | The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext… | |
| Modificada | Media (5) | 1.3% | — | Websense WEB FilterWebsense WEB Security | 26/8/2012 | 16/6/2026 | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 106 and 7.x before 7.1 allow remote attackers to cause a denial of service (filtering outage) via a crafted URL. | |
| Modificada | Alta (7.5) | 3.5% | — | Websense WEB FilterWebsense WEB SecurityWebsense WEB Security GatewayWebsense WEB Security Gateway Anywhere | 23/8/2012 | 16/6/2026 | The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows… | |
| Modificada | Media (5) | 1.6% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Coat appliance integration outage) via a long URL. | |
| Modificada | Media (5) | 1.4% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (5) | 1.2% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers to cause a denial of service (daemon exit) via a large volume of traffic. | |
| Modificada | Baja (2.1) | 0.39% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The Remote Filtering component in Websense Web Security and Web Filter before 7.1 Hotfix 66 allows local users to bypass filtering by (1) renaming the WDC.exe file or (2) deleting driver files. | |
| Modificada | Media (4.3) | 1.3% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 136 and 7.x before 7.1.1 on Windows allows remote attackers to cause a denial of service (filtering outage) via a crafted sequence of characters in a URI. | |
| Modificada | Media (4.3) | 1.5% | — | WebsenseWebsense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header. | |
| Modificada | Media (4.3) | 0.94% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a… | |
| Modificada | Media (4.3) | 1.1% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted… | |
| Modificada | Media (6.8) | 0.60% | — | Bloxx WEB Filtering | 9/6/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error pages containing XSS sequences, a different vulnerability than… | |
| Modificada | Media (5) | 2.1% | — | Bloxx WEB Filtering | 9/6/2012 | 16/6/2026 | Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header. | |
| Modificada | Media (5.8) | 1.2% | — | Bloxx WEB Filtering | 9/6/2012 | 16/6/2026 | Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach. | |
| Modificada | Media (6.8) | 0.77% | — | Bloxx WEB Filtering | 9/6/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bloxx Web Filtering before 5.0.14 allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions. | |
| Modificada | Media (4.3) | 1.3% | — | Bloxx WEB Filtering | 9/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Bloxx Web Filtering before 5.0.14 allow (1) remote attackers to inject arbitrary web script or HTML via web traffic that is examined within the Bloxx Reports component, and allow (2) remote authenticated administrators to inject arbitrary web script or HTML via… | |
| Modificada | Baja (3.5) | 1.5% | — | Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+1 | 19/12/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the… | |
| Modificada | Alta (7.5) | 2.5% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords. | |
| Modificada | Media (5) | 1.8% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. | |
| Modificada | Alta (7.5) | 1.1% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs. | |
| Modificada | Alta (7.5) | 0.98% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function. |