Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.32% | — | Cisco IOS XEAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.9) | 0.49% | 💥 PoC | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOSCisco IOS XE | 5/8/2026 | 17/9/2026 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper… | |
| Pendiente de análisis | Media (6.5) | 0.13% | — | Cisco Catalyst Sd-wan ManagerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included… | |
| Analizada | Media (6.5) | 0.33% | — | Cisco RoomosCisco Roomos Cloud | 5/8/2026 | 17/8/2026 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then… | |
| Analizada | Media (6.5) | 0.64% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 5/8/2026 | 16/9/2026 | — | |
| Analizada | Alta (8.8) | 0.73% | 💥 PoC | Cisco Unified Computing System | 5/8/2026 | 31/8/2026 | — | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | Cisco Integrated Management ControllerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Analizada | Alta (7.7) | 0.50% | — | Cisco IOS XE | 5/8/2026 | 17/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests.… | |
| Pendiente de análisis | Media (5) | 0.35% | — | Cisco Terminal Service AgentAI | 5/8/2026 | 6/8/2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least… | |
| Analizada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Crítica (9.8) | 0.57% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Crítica (9) | 0.38% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | |
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOS XE | 5/8/2026 | 28/9/2026 | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker… | |
| Pendiente de análisis | Media (4.9) | 0.71% | — | ISC DhcpAI | 5/8/2026 | 6/8/2026 | A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request. This request, containing an overly long… | |
| Aplazada | Alta (7.1) | 0.28% | — | Dynamic Pricing With Discount RulesAI | 1/8/2026 | 26/8/2026 | The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is… | |
| Analizada | Media (5.3) | 35% | ⚠ Explotación activa | Cisco Secure Firewall Management Center | 29/7/2026 | 16/9/2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Open-iscsiAI | 29/7/2026 | 30/7/2026 | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | Open-iscsiAI | 29/7/2026 | 30/7/2026 | An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. | |
| Pendiente de análisis | Media (6.9) | 0.58% | — | Open-iscsiAI | 29/7/2026 | 30/7/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. |