Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.42%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a browser that is accessing an affected device. This…
AnalizadaMedia (5.9)0.67%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent users from authenticating. This vulnerability is due to…
AnalizadaCrítica (9.9)1.2%—Cisco Adaptive Security Appliance Software23/10/202417/6/2026
A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted…
AnalizadaMedia (5.8)0.48%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected…
AnalizadaMedia (5.8)0.48%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected…
AnalizadaAlta (7.7)0.64%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the device. This vulnerability is due to insufficient input…
AplazadaAlta (8.6)0.59%—Cisco Adaptive Security Virtual ApplianceAICisco Secure Firewall Threat Defense VirtualAI23/10/202416/9/2026
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance…
AnalizadaAlta (7.2)16%—Ivanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
AnalizadaAlta (7.2)60%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
AnalizadaAlta (7.2)44%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/20241/10/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaCrítica (9.1)99%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Cloud Services Appliance19/9/202417/6/2026
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (7.2)89%⚠ Explotación activa💥 PoCIvanti Cloud Services Appliance10/9/202417/6/2026
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
AnalizadaMedia (4.7)0.38%—Oracle ZFS Storage Appliance KIT16/7/202417/6/2026
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks…
ModificadaMedia (5.4)0.38%—Trendmicro Interscan WEB Security Virtual Appliance10/6/202417/6/2026
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaCrítica (9.8)0.55%—Moneo ApplianceAI3/6/202417/6/2026
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.
AnalizadaMedia (5)0.33%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense22/5/202411/8/2026
A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to successfully establish a VPN session on an affected device. This…
AnalizadaMedia (5.8)0.40%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense22/5/202411/8/2026
A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability…
AnalizadaMedia (4.8)0.29%—Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An…
AplazadaMedia (6.8)0.37%—Veritas NetbackupAIVeritas Netbackup ApplianceAI3/5/202417/6/2026
A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a NetBackup administrator to modify the…
AnalizadaAlta (7.5)0.90%—IBM MQ Appliance27/4/202417/6/2026
IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.
ModificadaMedia (6.7)0.70%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense24/4/202411/8/2026
A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges.…
AnalizadaMedia (6)19%⚠ Explotación activaCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense24/4/202411/8/2026
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level…
AnalizadaAlta (8.6)71%⚠ Explotación activaCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense24/4/202411/8/2026
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability…
AnalizadaAlta (7.8)0.17%—Beyondtrust U-series Appliance19/4/202417/6/2026
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.
AnalizadaAlta (7.8)0.17%—Beyondtrust U-series Appliance19/4/202417/6/2026
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.