Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.4% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation of user privileges of web UI users. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 3.8% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.4) | 0.71% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with… | |
| Modificada | Alta (7.4) | 0.60% | 💥 PoC | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability… | |
| Modificada | Alta (7.4) | 1.2% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could… | |
| Modificada | Alta (8.6) | 2.4% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of SMS… | |
| Modificada | Media (6.5) | 0.64% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP… | |
| Modificada | Alta (7.8) | 0.45% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a… | |
| Modificada | Alta (8.8) | 2.2% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information. The vulnerability is due to improper access control to files within the web UI. An attacker could exploit this vulnerability by sending a malicious request to an… | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal… | |
| Modificada | Alta (8.6) | 2.2% | — | Cisco IOS XECisco IOS | 28/3/2019 | 17/6/2026 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco IOSCisco IOS XE | 28/3/2019 | 17/6/2026 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities… | |
| Modificada | Alta (8.6) | 2.6% | — | Cisco IOS XECisco IOS | 27/3/2019 | 17/6/2026 | A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual denial of service (DoS) condition on the affected device. The vulnerability is due to improper socket… | |
| Modificada | Media (6.8) | 2.0% | — | Cisco IOSCisco IOS XE | 10/1/2019 | 17/6/2026 | A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a state condition between the socket state and the transmission control block (TCB) state. While this vulnerability potentially… | |
| Modificada | Media (6.7) | 0.24% | — | Cisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are… | |
| Modificada | Alta (7.4) | 0.66% | — | Cisco IOSCisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory… | |
| Modificada | Alta (8.1) | 0.75% | — | Cisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected device. The… | |
| Modificada | Media (6.7) | 0.40% | — | Cisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms… | |
| Modificada | Media (6.8) | 2.1% | — | Cisco IOSCisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of crafted TACACS+ response packets by… | |
| Modificada | Media (6.7) | 0.39% | — | Cisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command… | |
| Modificada | Alta (8.6) | 4.1% | — | Cisco IOSCisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/E3 module on the ISR4451-X to reload, resulting in a denial of… | |
| Modificada | Media (6.7) | 0.49% | — | Cisco IOS XE | 5/10/2018 | 17/6/2026 | A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing to prevent access… |