Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.29% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and… | |
| Modificada | Alta (8.6) | 0.64% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of… | |
| Modificada | Media (5.8) | 0.52% | — | Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Unified Threat DefenseCisco Meraki MX Security Appliance Firmware | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this… | |
| Modificada | Alta (8.6) | 0.68% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 1/11/2023 | 11/8/2026 | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation… | |
| Modificada | Media (5.8) | 0.56% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an… | |
| Modificada | Media (5.8) | 0.48% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an… | |
| Modificada | Alta (8.6) | 0.65% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could… | |
| Modificada | Media (5.9) | 0.47% | — | Oracle SUN ZFS Storage Appliance KIT | 17/10/2023 | 17/6/2026 | Vulnerability in the Sun ZFS Storage Appliance product of Oracle Systems (component: Core). The supported version that is affected is 8.8.60. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance. Successful attacks of this vulnerability… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Crítica (9.1) | 25% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 6/9/2023 | 11/8/2026 | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated,… | |
| Modificada | Media (4.3) | 0.27% | — | Cisco Intersight Virtual Appliance | 16/8/2023 | 17/6/2026 | A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Alta (7.5) | 0.97% | — | IBM MQIBM MQ Appliance | 19/7/2023 | 17/6/2026 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397. | |
| Modificada | Media (4.8) | 0.58% | — | Sophos WEB Appliance | 30/6/2023 | 17/6/2026 | Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes. | |
| Modificada | Crítica (9.8) | 2.6% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot. | |
| Modificada | Alta (7.5) | 0.73% | — | Ucopia Wireless Appliance Firmware | 29/6/2023 | 17/6/2026 | An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. | |
| Modificada | Alta (7.2) | 0.62% | — | Veritas Netbackup Appliance | 29/6/2023 | 17/6/2026 | In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH. | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… | |
| Modificada | Media (5.4) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 28/6/2023 | 11/8/2026 | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly,… | |
| Modificada | Media (6.5) | 3.2% | — | Quest Kace Systems Deployment Appliance | 21/5/2023 | 17/6/2026 | There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled… | |
| Modificada | Alta (7.5) | 0.54% | — | Tribe29 Checkmk Appliance Firmware | 15/5/2023 | 17/6/2026 | Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. | |
| Modificada | Alta (7.5) | 0.95% | — | IBM MQ Appliance | 5/5/2023 | 17/6/2026 | IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418. |