Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1724 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.94%—Qnap Qufirewall19/12/202417/6/2026
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 (…
AplazadaAlta (8.8)0.70%—Cleantalk Spam Protection Antispam FirewallAI13/12/202417/6/2026
Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.
AnalizadaAlta (7.5)3.7%—Cleantalk Spam Protection, Antispam, Firewall26/11/202417/6/2026
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.3)0.66%—Cisco Secure Firewall Threat Defense15/11/202411/8/2026
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. This vulnerability is due to incomplete processing during deep packet inspection for…
AnalizadaMedia (4.3)0.28%—Cisco Secure Firewall Management Center15/11/202417/6/2026
—
AnalizadaMedia (4.3)0.28%—Cisco Secure Firewall Management Center15/11/202417/6/2026
A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privilege credentials on an affected device. This vulnerability is due to…
AnalizadaAlta (7.5)1.4%—Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine15/11/202411/8/2026
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by…
AnalizadaAlta (8.6)0.51%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This…
AnalizadaAlta (8.6)0.51%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is…
AnalizadaMedia (5.3)0.55%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software23/10/202411/8/2026
A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in…
AnalizadaMedia (6.7)0.18%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This…
AnalizadaMedia (6.5)0.49%—Cisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker must have a valid account…
AnalizadaMedia (5.8)16%⚠ Explotación activaCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software23/10/202411/8/2026
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An…
AnalizadaMedia (6.5)0.44%—Cisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input…
AnalizadaMedia (6.5)0.44%—Cisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input…
AnalizadaMedia (6.5)0.44%—Cisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input…
AnalizadaMedia (5.8)0.40%—Cisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (8.6)0.52%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…
AnalizadaCrítica (9.9)0.94%—Cisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaAlta (8.4)0.21%—Cisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaAlta (7.7)0.44%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the Dynamic Access Policies (DAP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly. To exploit this vulnerability, an attacker would need…
AnalizadaMedia (5.8)0.40%—Cisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Devices that are configured with Snort 2 are not affected by this…