Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
588 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.68% | — | Microfocus Arcsight Management Center | 16/6/2020 | 17/6/2026 | Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure. | |
| Modificada | Media (4.3) | 0.68% | — | Microfocus Arcsight Management Center | 16/6/2020 | 17/6/2026 | Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting unauthorized information disclosure. | |
| Modificada | Media (5.4) | 0.51% | — | Microfocus Arcsight Management Center | 16/6/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | |
| Modificada | Crítica (9.8) | 0.96% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS | 6/5/2020 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the FMC Software. The vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could… | |
| Modificada | Media (6.1) | 0.84% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.9) | 0.61% | — | Cisco Secure Firewall Threat DefenseCisco Secure Firewall Management Center | 6/5/2020 | 11/8/2026 | A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital… | |
| Modificada | Media (5.3) | 0.97% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (8.1) | 1.7% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by uploading a crafted… | |
| Modificada | Media (4.4) | 0.79% | — | Cisco Secure Firewall Management Center | 6/5/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.9) | 0.72% | — | Symantec Management Center | 10/4/2020 | 17/6/2026 | A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC. | |
| Modificada | Media (5.9) | 0.70% | — | Forcepoint Next Generation Firewall Security Management Center | 23/12/2019 | 17/6/2026 | Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the internal configuration database. When the database is corrupted, the SMC might produce an incorrect IPsec configuration for the Forcepoint Next Generation Firewall… | |
| Modificada | Media (5.3) | 0.97% | — | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 5/11/2019 | 11/8/2026 | A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper handling of… | |
| Modificada | Media (5.8) | 1.0% | — | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 5/11/2019 | 11/8/2026 | A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to insufficient… | |
| Modificada | Media (5.3) | 0.97% | — | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 5/11/2019 | 11/8/2026 | A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper detection of… | |
| Modificada | Media (5.8) | 9.4% | 💥 Exploit | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 5/11/2019 | 11/8/2026 | A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper reassembly of… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Secure Firewall Management Center | 16/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (5.4) | 0.66% | — | Cisco Firepower Management Center Firmware | 16/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Firepower Management Center 2600 FirmwareCisco Firepower Appliance 7030 FirmwareCisco Firepower Appliance 7110 FirmwareCisco Firepower Appliance 7115 Firmware+30 | 16/10/2019 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (4.8) | 0.80% | — | Cisco Firepower Management Center 2600 FirmwareCisco Firepower Appliance 7030 FirmwareCisco Firepower Appliance 7110 FirmwareCisco Firepower Appliance 7115 Firmware+30 | 16/10/2019 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (5.8) | 1.5% | — | Cisco Secure Firewall Management CenterCisco VDB Fingerprint Database | 2/10/2019 | 17/6/2026 | A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates… | |
| Modificada | Media (6.5) | 1.9% | — | Cisco Firepower 9300 FirmwareCisco Firepower Extensible Operating SystemCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 2/10/2019 | 11/8/2026 | A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense (FTD) Software, Cisco Firepower Management Center (FMC) Software, and Cisco FXOS Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The… | |
| Modificada | Media (4.9) | 5.1% | — | Cisco Secure Firewall Management Center | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An… |