Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.39% | — | Cisco 350 Series Managed SwitchesAICisco 350x Series Stackable Managed SwitchesAI | 6/5/2026 | 17/6/2026 | This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Cisco Enterprise Chat AND EmailAI | 6/5/2026 | 17/6/2026 | A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. | |
| Analizada | Media (6.4) | 0.21% | 💥 PoC | Cisco IOT Field Network Director | 6/5/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.2) | 0.30% | — | Cisco Unity Connection | 6/5/2026 | 8/7/2026 | A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP… | |
| Analizada | Alta (8.8) | 0.71% | — | Cisco Unity Connection | 6/5/2026 | 1/7/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a… | |
| Analizada | Media (6.7) | 0.91% | — | Cisco Intersight Device Connector | 28/4/2026 | 17/6/2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network… | |
| Analizada | Crítica (9.9) | 5.6% | — | Cisco Identity Services Engine | 15/4/2026 | 29/6/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Cisco Webex ServicesAI | 15/4/2026 | 17/6/2026 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an… | |
| Analizada | Crítica (9.9) | 6.0% | 💥 PoC | Cisco Identity Services Engine | 15/4/2026 | 8/7/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Webex Contact Center | 15/4/2026 | 1/7/2026 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed. This vulnerability existed… | |
| Pendiente de análisis | Media (5.5) | 0.13% | — | Cisco Thousandeyes Enterprise AgentAI | 15/4/2026 | 17/6/2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system of an affected… | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 15/4/2026 | 17/6/2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Identity Services Engine | 15/4/2026 | 2/7/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system. | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system. | |
| Analizada | Media (6.5) | 0.23% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to… | |
| Analizada | Media (4.7) | 0.20% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a… | |
| Analizada | Media (6.1) | 0.19% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Analizada | Media (4.9) | 6.5% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper… | |
| Analizada | Crítica (9.9) | 10% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This… | |
| Analizada | Media (4.9) | 0.49% | — | Cisco Nexus Dashboard InsightsCisco Nexus Dashboard | 1/4/2026 | 1/7/2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a… | |
| Analizada | Crítica (9.8) | 0.91% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 1/7/2026 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could… |