Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.53% | — | Cisco IOSCisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to crash and reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for… | |
| Modificada | Alta (8.6) | 1.6% | — | Cisco IOSCisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability occurs because the regular expression (regex) engine that is used with the… | |
| Modificada | Alta (8.6) | 1.5% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL that is tied to the RESTCONF or NETCONF-YANG feature. An attacker could… | |
| Modificada | Alta (7.8) | 0.32% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient enforcement of the… | |
| Modificada | Alta (7.8) | 0.38% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The… | |
| Modificada | Alta (8.8) | 0.98% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is… | |
| Modificada | Alta (7.2) | 0.32% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections. The vulnerability occurs because the USB… | |
| Modificada | Alta (7.8) | 0.34% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container as well as on the underlying Linux… | |
| Modificada | Alta (7.4) | 0.64% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition… | |
| Modificada | Alta (8.6) | 1.5% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 1.8% | — | Cisco IOS XE | 24/9/2020 | 17/6/2026 | Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this… | |
| Modificada | Alta (8.8) | 0.97% | — | Cisco IOSCisco IOS XE | 23/9/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit… | |
| Modificada | Crítica (9.8) | 3.9% | — | Cisco Sd-wanCisco IOS XE Sd-wan | 31/7/2020 | 17/6/2026 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful… | |
| Modificada | Alta (7.7) | 1.6% | — | Cisco IOSCisco IOS XEOracle Goldengate Management Pack | 3/6/2020 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the… | |
| Modificada | Alta (7.7) | 1.0% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Services Router model ASR920-12SZ-IM could allow an authenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of data that is returned for Cisco… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco IOSCisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations. The vulnerability is due to incorrect handling of crafted IKEv2 SA-Init packets. An… | |
| Modificada | Alta (8.8) | 5.3% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC for the administration GUI. An attacker… | |
| Modificada | Alta (8.6) | 1.8% | — | Cisco IOSCisco IOS XECisco Nx-os | 3/6/2020 | 17/6/2026 | A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because crafted SXP… | |
| Modificada | Crítica (9.8) | 3.4% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The vulnerability is due to incorrect handling of requests for authorization… | |
| Modificada | Alta (8.6) | 1.6% | — | Cisco IOSCisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on… | |
| Modificada | Alta (8.6) | 2.1% | — | Cisco IOSCisco IOS XE | 3/6/2020 | 17/6/2026 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to… | |
| Modificada | Alta (8.8) | 1.8% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to inject IOS commands to an affected device. The injected commands should require a higher privilege level in order to be executed. The vulnerability is due to… | |
| Modificada | Media (4.9) | 1.9% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this… | |
| Modificada | Media (4.3) | 0.44% | — | Cisco IOS XE | 3/6/2020 | 17/6/2026 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at a specific endpoint of the web UI. An attacker could exploit… |