Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 1.2% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. | |
| Analizada | Media (5.3) | 0.34% | — | IBM MQ Appliance | 19/12/2024 | 17/6/2026 | IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size. | |
| Analizada | Media (6.5) | 0.70% | — | IBM MQ ApplianceIBM MQ FOR HPE Nonstop | 18/12/2024 | 17/6/2026 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Menlo On-premise ApplianceAI | 14/12/2024 | 17/6/2026 | In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+. | |
| Analizada | Alta (7.2) | 23% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| Analizada | Alta (7.2) | 7.7% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 4.9% | — | Ivanti Cloud Services Appliance | 10/12/2024 | 17/6/2026 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access | |
| Analizada | Media (6.7) | 0.17% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Crítica (9.8) | 0.76% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Aplazada | Alta (8.8) | 0.34% | — | Nvidia UFM EnterpriseAINvidia UFM ApplianceAINvidia UFM CyberaiAI | 6/12/2024 | 17/6/2026 | NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial… | |
| Aplazada | Media (6.1) | 0.43% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to… | |
| Analizada | Alta (7.5) | 0.84% | — | Cisco Email Security Appliance | 18/11/2024 | 17/6/2026 | A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability… | |
| Analizada | Alta (8.6) | 0.92% | — | Cisco Adaptive Security Appliance Software | 18/11/2024 | 17/6/2026 | A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerability is due to improper error handling on established SSL/TLS… | |
| Analizada | Media (5.3) | 0.49% | — | Cisco Adaptive Security Appliance Software | 23/10/2024 | 17/6/2026 | A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a logic error when an SSH session is established. An attacker could… | |
| Analizada | Alta (8.6) | 0.51% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This… | |
| Analizada | Alta (8.6) | 0.51% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is… | |
| Analizada | Media (5.3) | 0.55% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 23/10/2024 | 11/8/2026 | A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in… | |
| Analizada | Media (6.7) | 0.18% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This… | |
| Analizada | Media (5.8) | 16% | ⚠ Explotación activa | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 23/10/2024 | 11/8/2026 | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An… | |
| Analizada | Alta (8.6) | 0.52% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Analizada | Alta (7.7) | 0.44% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need… | |
| Analizada | Alta (8.6) | 0.52% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due… | |
| Analizada | Media (5.8) | 0.45% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an… | |
| Analizada | Media (6.1) | 0.41% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This… | |
| Aplazada | Media (6) | 0.17% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAICisco FxosAI | 23/10/2024 | 17/6/2026 | A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid… |