Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

433 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)0.23%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Vsmart Controller Firmware+96/5/202117/6/2026
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-supplied input parameters of a specific CLI command. An attacker could…
ModificadaAlta (8.8)1.6%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about…
ModificadaMedia (5.4)0.64%—Cisco Sd-wan Vmanage6/5/202117/6/2026
A vulnerability in an API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the application web-based interface. This vulnerability exists because the API does not properly validate user-supplied input. An attacker…
ModificadaAlta (7.2)1.8%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about…
ModificadaAlta (8.8)1.6%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about…
ModificadaMedia (5.3)1.2%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit…
ModificadaCrítica (9.8)2.0%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about…
ModificadaAlta (8.8)0.44%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
A vulnerability in the web-based messaging service interface of Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to bypass authentication and authorization and modify the configuration of an affected system. To exploit this vulnerability, the attacker must be able to access an associated…
ModificadaAlta (7.5)2.1%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage6/5/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about…
ModificadaAlta (7.8)1.8%💥 PoCCisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage8/4/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)1.9%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage8/4/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.8)0.55%—Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage8/4/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (6.6)0.25%—Cisco IOS XE Sd-wan24/3/202117/6/2026
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration. This vulnerability occurs because the default…
ModificadaMedia (6.7)0.28%—Cisco IOS XECisco IOS XE Sd-wan24/3/202117/6/2026
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker could exploit these vulnerabilities by…
ModificadaMedia (6.7)0.59%—Cisco IOS XECisco IOS XE Sd-wan24/3/202117/6/2026
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker could exploit these vulnerabilities by…
AnalizadaAlta (7.3)0.34%—Cisco IOS XECisco IOS XE Sd-wan24/3/20217/10/2026
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability…
ModificadaAlta (7.5)1.4%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (5.5)0.31%—Cisco Sd-wan Vmanage20/1/202117/6/2026
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read sensitive database files on an affected system. The vulnerability is due to insufficient user authorization. An attacker could exploit this vulnerability by accessing the vshell of an affected system. A…
ModificadaMedia (4.4)0.32%—Cisco Sd-wan FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information on an affected device. The vulnerability is due to insufficient input validation of requests that are sent to the iperf tool. An attacker could exploit this vulnerability by sending a…
ModificadaCrítica (9.1)1.4%—Cisco Sd-wan Vmanage20/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An…
ModificadaMedia (6.5)1.4%—Cisco Sd-wan Vmanage20/1/202117/6/2026
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker…
ModificadaMedia (4.3)1.3%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Sd-wan Vbond Orchestrator20/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access.…
ModificadaMedia (6.5)1.6%—Cisco Catalyst Sd-wan Manager20/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access.…
ModificadaAlta (8.8)1.7%—Cisco Catalyst Sd-wan Manager20/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access.…
ModificadaCrítica (9.8)2.1%—Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+120/1/202117/6/2026
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Orbitaley — Vulnerabilidades