Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 7.8% | — | Cisco Prime Collaboration Provisioning | 22/5/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and… | |
| Modificada | Media (6.5) | 5.9% | — | Cisco Prime Collaboration Provisioning | 22/5/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and… | |
| Modificada | Media (6.5) | 9.7% | — | Cisco Prime Collaboration Provisioning | 22/5/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and… | |
| Modificada | Crítica (9.8) | 62% | 💥 Exploit | Cisco Prime Collaboration Provisioning | 18/5/2017 | 17/6/2026 | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access… | |
| Modificada | Alta (7.5) | 6.2% | — | Cisco Prime Collaboration Provisioning | 18/5/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when… | |
| Modificada | Alta (7.8) | 1.9% | — | Softbank Primedrive Desktop Application | 12/5/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.74% | — | Softbank Primedrive Desktop Application | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in PrimeDrive Desktop Application 1.4.3 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (5.8) | 2.0% | — | Cisco Prime Network Registrar | 20/4/2017 | 17/6/2026 | A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected system. The vulnerability is due to incomplete DNS packet… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Prime Infrastructure | 20/4/2017 | 17/6/2026 | A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of some parameters passed… | |
| Modificada | Media (6.5) | 2.1% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 7/4/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use this information to conduct additional reconnaissance… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Prime Infrastructure | 7/4/2017 | 17/6/2026 | A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCuw63001 CSCuw63003. Known Affected Releases: 2.2(2).… | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Prime Optical | 17/3/2017 | 17/6/2026 | A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The attacker must have valid credentials for the device. More… | |
| Modificada | Media (5.4) | 0.96% | — | Cisco Prime Infrastructure | 17/3/2017 | 17/6/2026 | An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Information: CSCuy36192. Known Affected Releases: 3.1(1) 3.1(1). | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Prime Service Catalog | 17/3/2017 | 17/6/2026 | A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc79842 CSCvc79846 CSCvc79855 CSCvc79873 CSCvc79882 CSCvc79891.… | |
| Modificada | Media (6.1) | 1.5% | — | Cisco Prime Collaboration Assurance | 22/2/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance… | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Prime Collaboration Assurance | 22/2/2017 | 17/6/2026 | A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco… | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Prime Collaboration Assurance | 22/2/2017 | 17/6/2026 | A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0). | |
| Modificada | Media (5.4) | 1.1% | — | Cisco Prime Service Catalog | 3/2/2017 | 17/6/2026 | A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: 10.0_R2_tanggula. | |
| Modificada | Crítica (10) | 4.1% | — | Cisco Prime Home | 1/2/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processing error in the role-based access control (RBAC) of URLs. An attacker could exploit this… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco Prime Collaboration Assurance | 14/12/2016 | 17/6/2026 | A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface. More Information: CSCut43268. Known Affected Releases: 10.5(1) 10.6. | |
| Modificada | Crítica (9.8) | 2.7% | — | Cisco Prime Home | 3/11/2016 | 17/6/2026 | A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. Cisco Prime Home versions 5.1.1.6 and earlier and 5.2.2.2 and earlier have been confirmed to be… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Prime Collaboration Provisioning | 3/11/2016 | 17/6/2026 | Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCut43061 CSCut43066 CSCut43736 CSCut43738… | |
| Modificada | Alta (8.8) | 3.0% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 27/10/2016 | 17/6/2026 | A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335.… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Prime Home | 24/9/2016 | 17/6/2026 | Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814. | |
| Modificada | Alta (8.1) | 2.2% | — | EMC Authentication Manager Prime | 22/8/2016 | 17/6/2026 | The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users to cause a denial of service (PIN change for an arbitrary user) via a modified token serial number within a PIN change request, related to a "direct object reference… |