Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.27% | — | Cisco Evolved Programmable Network Manager | 1/4/2026 | 2/7/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API… | |
| Analizada | Alta (7.3) | 0.27% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 8/7/2026 | A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unified Computing System | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could… | |
| Analizada | Media (6.5) | 0.72% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Media (6.5) | 0.93% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.… | |
| Pendiente de análisis | Crítica (9.8) | 0.99% | — | Cisco Integrated Management ControllerAI | 1/4/2026 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of… | |
| Analizada | Media (6.5) | 0.29% | — | Cisco Nexus Dashboard | 1/4/2026 | 8/7/2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An… | |
| En análisis | Media (6.1) | 0.24% | — | Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI | 1/4/2026 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit… | |
| Pendiente de análisis | Alta (7.7) | 0.28% | — | Cisco IOSAICisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Cisco IOS XEAICisco MerakiAI | 25/3/2026 | 17/6/2026 | A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path… | |
| Pendiente de análisis | Media (5.4) | 0.28% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability exists because parameters that are received… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Cisco IOS XEAICisco IOXAI | 25/3/2026 | 17/6/2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An… | |
| Pendiente de análisis | Media (4.8) | 0.19% | — | Cisco IOS XEAICisco IOXAI | 25/3/2026 | 17/6/2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An attacker could exploit this vulnerability by… | |
| Analizada | Media (5.4) | 0.16% | — | Cisco Catalyst Sd-wan Manager | 25/3/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker… | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Cisco IOS XE Wireless Controller SoftwareAI | 25/3/2026 | 17/6/2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of a malformed SCP request. An attacker could… | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE | 25/3/2026 | 17/9/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,… | |
| Analizada | Media (6.1) | 0.15% | — | Cisco IOS XE | 25/3/2026 | 28/9/2026 | A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15… |