Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | ISC Bind | 20/5/2026 | 17/9/2026 | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS… | |
| Analizada | Baja (2.1) | 0.27% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions 2026.1.4, 2026.3.1,… | |
| Analizada | Media (6) | 0.30% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are intended exclusively for categories they… | |
| Analizada | Media (5.3) | 0.38% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and… | |
| Analizada | Crítica (9.3) | 0.96% | ⚠ Explotación activa | Disc-soft Daemon Tools | 15/5/2026 | 17/6/2026 | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc… | |
| Analizada | Alta (8.6) | 1.0% | 💥 PoC | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML… | |
| Analizada | Media (5.4) | 0.19% | — | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive… | |
| Analizada | Media (5.4) | 0.19% | — | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information… | |
| Analizada | Crítica (10) | 92% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 14/5/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Analizada | Media (5.5) | 0.16% | — | Projectdiscovery Nuclei | 8/5/2026 | 17/6/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This… | |
| Analizada | Media (5.3) | 0.44% | — | Projectdiscovery Nuclei | 8/5/2026 | 17/6/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing… | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | Cisco SlidoAI | 6/5/2026 | 17/6/2026 | A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed. This vulnerability existed because of the… | |
| Analizada | Media (5.3) | 0.27% | — | Cisco Identity Services Engine | 6/5/2026 | 29/6/2026 | A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this… | |
| Analizada | Media (4.3) | 0.22% | — | Cisco Identity Services Engine | 6/5/2026 | 1/7/2026 | A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on… | |
| Analizada | Media (4.3) | 0.21% | — | Cisco Prime Infrastructure | 6/5/2026 | 29/6/2026 | A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this… | |
| Pendiente de análisis | Ninguna (0) | 0.31% | — | Cisco Crosswork Network ControllerAICisco Network Services OrchestratorAI | 6/5/2026 | 17/6/2026 | Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis,… | |
| Pendiente de análisis | Alta (7.7) | 0.39% | — | Cisco 350 Series Managed SwitchesAICisco 350x Series Stackable Managed SwitchesAI | 6/5/2026 | 17/6/2026 | This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a… | |
| Pendiente de análisis | Media (4.3) | 0.13% | — | Cisco Enterprise Chat AND EmailAI | 6/5/2026 | 17/6/2026 | A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. | |
| Analizada | Media (6.4) | 0.21% | 💥 PoC | Cisco IOT Field Network Director | 6/5/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.2) | 0.30% | — | Cisco Unity Connection | 6/5/2026 | 8/7/2026 | A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP… | |
| Analizada | Alta (8.8) | 0.71% | — | Cisco Unity Connection | 6/5/2026 | 1/7/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a… | |
| Analizada | Media (6.7) | 0.91% | — | Cisco Intersight Device Connector | 28/4/2026 | 17/6/2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network… | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Purview Ediscovery | 23/4/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. |