Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

7116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.27%—Cisco Evolved Programmable Network Manager1/4/20262/7/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API…
AnalizadaAlta (7.3)0.27%—Cisco Smart Software Manager On-prem1/4/20268/7/2026
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by…
AnalizadaMedia (6.5)0.39%—Cisco Unified Computing System1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could…
AnalizadaMedia (6.5)0.72%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied…
AnalizadaMedia (6.5)0.93%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied…
AnalizadaAlta (8.8)1.1%—Cisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.…
Pendiente de análisisCrítica (9.8)0.99%—Cisco Integrated Management ControllerAI1/4/202617/6/2026
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could…
AnalizadaMedia (4.8)0.24%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.24%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.22%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.17%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (6.1)0.18%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of…
AnalizadaMedia (6.5)0.29%—Cisco Nexus Dashboard1/4/20268/7/2026
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An…
En análisisMedia (6.1)0.24%—Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI1/4/202617/6/2026
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit…
Pendiente de análisisAlta (7.7)0.28%—Cisco IOSAICisco IOS XEAI25/3/202617/6/2026
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied…
Pendiente de análisisMedia (6.1)0.15%—Cisco IOS XEAICisco MerakiAI25/3/202617/6/2026
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path…
Pendiente de análisisMedia (5.4)0.28%—Cisco IOS XEAI25/3/202617/6/2026
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability exists because parameters that are received…
Pendiente de análisisMedia (5.3)0.29%—Cisco IOS XEAICisco IOXAI25/3/202617/6/2026
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An…
Pendiente de análisisMedia (4.8)0.19%—Cisco IOS XEAICisco IOXAI25/3/202617/6/2026
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is…
Pendiente de análisisMedia (6.5)0.09%—Cisco IOS XEAI25/3/202617/6/2026
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An attacker could exploit this vulnerability by…
AnalizadaMedia (5.4)0.16%—Cisco Catalyst Sd-wan Manager25/3/202629/6/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker…
Pendiente de análisisAlta (8.6)0.35%—Cisco IOS XE Wireless Controller SoftwareAI25/3/202617/6/2026
A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is…
Pendiente de análisisMedia (6.5)0.09%—Cisco IOS XEAI25/3/202617/6/2026
A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of a malformed SCP request. An attacker could…
AnalizadaAlta (8.6)0.35%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE25/3/202617/9/2026
A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,…
AnalizadaMedia (6.1)0.15%—Cisco IOS XE25/3/202628/9/2026
A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15…