Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.16%—Forcepoint WEB Security16/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6.
AplazadaCrítica (9.6)0.42%—Forcepoint WEB SecurityAI22/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows administrators to generate detailed reports on user requests made through the Web proxy. It has been determined…
ModificadaMedia (5.4)0.38%—Trendmicro Interscan WEB Security Virtual Appliance10/6/202417/6/2026
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaMedia (6.1)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaMedia (6.1)0.51%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…
ModificadaMedia (5.4)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaCrítica (9.8)0.51%—Forcepoint Email SecurityForcepoint WEB Security15/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules) allows Reflected…
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_form.mhtml modules) allows Reflected…
ModificadaMedia (6.1)0.35%—Forcepoint Cloud Security GatewayForcepoint WEB Security29/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules)…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaCrítica (9.8)0.81%—Forcepoint Cloud Security GatewayForcepoint Data Loss PreventionForcepoint Email SecurityForcepoint ONE Endpoint With Policy Engine+112/9/202217/6/2026
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security Gateway prior to June 20, 2022. The XML…
ModificadaMedia (5.3)0.93%—Cisco WEB Security Appliance6/4/202217/6/2026
A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling…
ModificadaAlta (8.6)1.7%—Cisco Ironport WEB Security ApplianceCisco Secure Firewall Management CenterCisco Firepower Management Center Virtual Appliance Firmware18/8/202117/6/2026
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data from a compromised…
ModificadaAlta (8.8)1.9%—Cisco WEB Security ApplianceCisco Asyncos8/7/202117/6/2026
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An…
ModificadaMedia (5.4)1.4%—Trendmicro Interscan WEB Security Virtual Appliance17/6/202117/6/2026
Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.
ModificadaAlta (7.4)0.67%—Cisco Email Security ApplianceCisco AsyncosCisco WEB Security Appliance16/6/202117/6/2026
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This…
ModificadaMedia (6.5)1.0%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security ApplianceCisco Ironport WEB Security Appliance6/5/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The…
ModificadaMedia (6.1)0.70%—Cisco WEB Security Appliance6/5/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of…
ModificadaAlta (7.5)1.0%—Forcepoint Data Loss PreventionForcepoint Email SecurityForcepoint WEB Security Content Gateway8/4/202117/6/2026
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
ModificadaMedia (5.5)0.62%—Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+153/3/202117/6/2026
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ModificadaMedia (4.8)0.79%—Cisco WEB Security Virtual Appliance20/1/202117/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based…
ModificadaMedia (5.3)1.1%—Cisco Content Security Management ApplianceCisco Email Security ApplianceCisco WEB Security Appliance20/1/202117/6/2026
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain…
ModificadaCrítica (9.8)64%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.
ModificadaCrítica (9.8)2.7%—Trendmicro Interscan WEB Security Virtual Appliance17/12/202017/6/2026
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.