Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… | |
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Prime Collaboration Assurance | 3/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance (PCA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to the insufficient… | |
| Modificada | Media (6.5) | 2.1% | — | Cprime Power Scripts | 18/4/2019 | 17/6/2026 | The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal. | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Prime Network Registrar | 18/4/2019 | 17/6/2026 | A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due to incomplete user-supplied input validation when a custom extension… | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco Prime Collaboration Assurance | 21/2/2019 | 17/6/2026 | A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.4) | 0.85% | — | Cisco Prime Infrastructure | 21/2/2019 | 17/6/2026 | A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI. The vulnerability is due to improper… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Prime Infrastructure | 23/1/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Prime Infrastructure | 10/1/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (5.4) | 0.88% | — | Cisco Prime Infrastructure | 10/1/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The vulnerability is due to insufficient validation of… | |
| Modificada | Crítica (9.8) | 3.7% | — | Cisco Prime License Manager | 28/11/2018 | 17/6/2026 | A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted… | |
| Modificada | Media (5.4) | 0.92% | — | Cisco Prime Service Catalog | 8/11/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is… | |
| Modificada | Media (6.5) | 2.5% | — | Cisco Prime Collaboration | 8/11/2018 | 17/6/2026 | A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to overwrite files on the file system. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using a specific UI input field to provide a custom… | |
| Modificada | Media (6.5) | 1.2% | — | Cisco Prime Collaboration Assurance | 17/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the… | |
| Modificada | Alta (8.1) | 5.4% | — | Cisco Prime Data Center Network Manager | 5/10/2018 | 17/6/2026 | A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of user requests within the management interface. An attacker… | |
| Modificada | Media (4.3) | 1.0% | — | Cisco Prime Infrastructure | 5/10/2018 | 17/6/2026 | A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request… | |
| Modificada | Media (4.3) | 1.0% | — | Cisco Prime Infrastructure | 5/10/2018 | 17/6/2026 | A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cisco Prime Collaboration | 5/10/2018 | 17/6/2026 | A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. The vulnerability is due to a hard-coded password that, in… | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Cisco Prime Infrastructure | 5/10/2018 | 17/6/2026 | A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco Prime Collaboration Assurance | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of… | |
| Modificada | Alta (8.6) | 3.5% | — | Cisco Prime Access RegistrarCisco Prime Access Registrar Jumpstart | 5/10/2018 | 17/6/2026 | A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports.… | |
| Modificada | Media (6.5) | 2.7% | — | Cisco Prime CollaborationCisco Prime Collaboration Provisioning | 1/8/2018 | 17/6/2026 | A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. An attacker could exploit this vulnerability by changing a… | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Quartus Prime Programmer AND Tools | 10/7/2018 | 17/6/2026 | Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Quartus Prime | 10/7/2018 | 17/6/2026 | Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.7% | 💥 PoC | Inversoft Prime-jwt | 26/6/2018 | 17/6/2026 | inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm… |