Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
433 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.63% | 💥 PoC | Cisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Sd-wan Vsmart ControllerCisco Sd-wan | 30/9/2022 | 17/6/2026 | Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the… | |
| Analizada | Alta (7.8) | 12% | ⚠ Explotación activa | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vedge CloudCisco Sd-wan Vsmart Controller+1 | 30/9/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the… | |
| Modificada | Alta (8.8) | 0.35% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 8/9/2022 | 17/6/2026 | A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists because the messaging server container ports… | |
| Modificada | Media (4.4) | 0.24% | — | Cisco Catalyst Sd-wan Manager | 4/5/2022 | 17/6/2026 | A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this… | |
| Modificada | Alta (7.3) | 0.60% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 0.49% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Sd-wan Vedge Router | 15/4/2022 | 17/6/2026 | A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan SolutionCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vedge Cloud+3 | 15/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device.… | |
| Modificada | Baja (2.7) | 0.66% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+10 | 13/4/2022 | 17/6/2026 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | |
| Modificada | Media (6.1) | 0.53% | — | Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+8 | 13/4/2022 | 17/6/2026 | Reflected cross site scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Sd-wan | 7/12/2021 | 17/6/2026 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (7.8) | 0.31% | — | Cisco IOS XECisco IOS XE Sd-wan | 21/10/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device… | |
| Modificada | Alta (7.5) | 12% | — | Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+14 | 14/10/2021 | 17/6/2026 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a… | |
| Modificada | Media (5.3) | 2.1% | — | PHPNetapp Clustered Data OntapOracle Sd-wan Aware | 4/10/2021 | 17/6/2026 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading… | |
| Modificada | Media (6.7) | 0.36% | — | Cisco IOS XECisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.7) | 0.37% | — | Cisco Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation on certain CLI commands. An… | |
| Modificada | Media (6.7) | 0.36% | — | Cisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could… | |
| Modificada | Media (6) | 0.27% | — | Cisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user. This vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 23/9/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker… |