Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%—Invisioncommunity Invision Power BoardInvisionpower Ip.nexus3/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.6)2.0%—Cisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric InterconnectCisco Unified Computing System 6296up Fabric Interconnect+2326/5/201417/6/2026
Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2…
ModificadaAlta (7.8)1.9%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+326/5/201417/6/2026
The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915.
ModificadaAlta (7.1)1.9%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+126/5/201416/6/2026
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
ModificadaMedia (5)1.2%—Cisco Nexus 1000v Intercloud7/5/201417/6/2026
Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2) IGMPv3 packets, aka Bug ID CSCug61691.
ModificadaMedia (4.6)0.30%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+17/5/201417/6/2026
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
ModificadaAlta (7.5)2.1%—Sonatype Nexus1/4/201417/6/2026
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
ModificadaAlta (7.5)3.0%—Sonatype Nexus17/1/201417/6/2026
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
ModificadaMedia (6.8)0.32%—Cisco Nexus 1000v18/11/201316/6/2026
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands…
ModificadaMedia (4)2.1%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+15/10/201316/6/2026
The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089.
ModificadaMedia (6.8)0.38%—Cisco Nx-osCisco Nexus 1000v10/7/201316/6/2026
The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.
ModificadaMedia (5)1.8%—Cisco Nx-osCisco Nexus 1000v29/5/201316/6/2026
Cisco NX-OS on the Nexus 1000V does not assign the proper priority to heartbeat messages from a Virtual Ethernet Module (VEM) to a Virtual Supervisor Module (VSM), which allows remote attackers to cause a denial of service (false VEM unavailability report) via a flood of UDP packets, aka Bug ID CSCud14840.
ModificadaMedia (5.8)0.67%—Cisco Nx-osCisco Nexus 1000v29/5/201316/6/2026
The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a crafted certificate, aka Bug ID CSCud14837.
ModificadaMedia (6.1)0.71%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+129/4/201316/6/2026
The Ethernet frame-forwarding implementation in Cisco NX-OS on Nexus 7000 devices allows remote attackers to cause a denial of service (forwarding loop and service outage) via a crafted frame, aka Bug ID CSCug47098.
ModificadaAlta (9.3)2.4%—Cisco Adaptive Security Appliance Device ManagerCisco Nexus 5000Cisco Nexus 5010Cisco Nexus 5010p Switch+625/4/201316/6/2026
The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote attackers to execute arbitrary commands on Windows client machines via a crafted element-manager.jnlp file, aka Bug IDs CSCty17417 and CSCty10802.
ModificadaAlta (7.8)1.9%—Cisco Nx-osCisco Nexus 5548pCisco Nexus 5548upCisco Nexus 5596up+825/4/201316/6/2026
Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 devices before 2.0(1w) allows remote attackers to cause a denial of service (device reload) by sending a jumbo packet to the management interface, aka Bug IDs CSCtx17544,…
ModificadaAlta (9)3.4%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+225/4/201316/6/2026
Buffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allows remote authenticated users to execute arbitrary code via a crafted SNMP request, aka Bug ID CSCtx54822.
ModificadaAlta (9)3.4%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+225/4/201316/6/2026
Multiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allow remote authenticated users to execute arbitrary code via a crafted SNMP request, aka Bug ID…
ModificadaAlta (8.3)1.4%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+2325/4/201316/6/2026
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V…
ModificadaMedia (5)2.1%—Cisco Nx-osCisco Nexus 700013/2/201316/6/2026
Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial of service (M1-Series module reload) via crafted packets, aka Bug ID CSCud15673.
ModificadaMedia (4.9)0.90%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+119/1/201316/6/2026
Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow remote authenticated users to cause a denial of service (memory consumption) via a crafted configuration that references interfaces that do not exist on the new card, aka Bug ID CSCud44300.
ModificadaMedia (6.1)0.69%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+116/9/201216/6/2026
Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large number of ARP packets, aka Bug ID CSCtr44822.
ModificadaMedia (5)1.2%—Cisco Nx-osCisco Nexus 50006/8/201216/6/2026
The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Nexus 5000 series switches allows remote attackers to cause a denial of service (device reload) via IGMP packets, aka Bug ID CSCts46521.
ModificadaAlta (7.8)1.8%—Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+16/8/201216/6/2026
Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) policy is configured for Reset, allows remote attackers to cause a denial of service (device reset) via a malformed Cisco Discovery Protocol (CDP) packet, aka Bug IDs CSCtk34535 and CSCtk19132.
ModificadaAlta (7.8)1.3%—Cisco Nx-osCisco Nexus 2148t FEX SwitchCisco Nexus 2224tp FEX SwitchCisco Nexus 2232pp FEX Switch+83/5/201216/6/2026
Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.