Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 1.1% | — | Cisco Unified Contact Center Express | 5/11/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a… | |
| Analizada | Crítica (9.8) | 0.92% | — | Cisco Unified Contact Center Express | 5/11/2025 | 17/6/2026 | A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the… | |
| Analizada | Crítica (9.8) | 0.87% | — | Cisco Unified Contact Center Express | 5/11/2025 | 17/6/2026 | A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are… | |
| Analizada | Alta (7.5) | 0.71% | 💥 PoC | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a… | |
| Analizada | Media (4.9) | 0.30% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 3.9% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Aplazada | Media (5.8) | 0.38% | — | Cisco Snort 3AI | 15/10/2025 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could… | |
| Analizada | Crítica (9.1) | 0.48% | — | Cisco Snort | 15/10/2025 | 17/9/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. This vulnerability is due to an error in the logic of buffer handling when the MIME… | |
| Analizada | Media (6.1) | 0.29% | — | Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+13 | 15/10/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web UI of an affected… | |
| Analizada | Alta (7.5) | 0.48% | — | Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+13 | 15/10/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to a buffer overflow when an affected… | |
| Analizada | Media (4.9) | 0.36% | — | Cisco Telepresence Collaboration EndpointCisco Roomos | 15/10/2025 | 17/6/2026 | A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid… | |
| Aplazada | Media (4.8) | 0.22% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI | 1/10/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Cyber Vision Center | 1/10/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Cyber Vision Center | 1/10/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Crítica (9) | 6.9% | — | Cisco IOS XRCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE+1 | 25/9/2025 | 11/8/2026 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or… | |
| Analizada | Alta (8.6) | 87% | ⚠ Explotación activa💥 Exploit | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 25/9/2025 | 11/8/2026 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS)… | |
| Analizada | Crítica (9.9) | 71% | ⚠ Explotación activa💥 PoC | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 25/9/2025 | 11/8/2026 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of… | |
| Analizada | Alta (7.7) | 39% | ⚠ Explotación activa💥 PoC | Cisco IOS XE Sd-wanCisco IOS XECisco IOS | 24/9/2025 | 25/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco… | |
| Analizada | Media (6.7) | 0.16% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to… | |
| Analizada | Alta (7.7) | 0.39% | — | Cisco IOS | 24/9/2025 | 25/9/2026 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an… | |
| Aplazada | Media (5.3) | 0.34% | — | Cisco IOS XEAICisco Catalyst 9500xAICisco Catalyst 9600xAI | 24/9/2025 | 25/9/2026 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. This vulnerability is due to the flooding of traffic from an unlearned MAC address… | |
| Analizada | Alta (8.6) | 0.44% | — | Cisco IOS XE | 24/9/2025 | 28/9/2026 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition. This vulnerability is due to improper handling of malformed Control and Provisioning… | |
| Aplazada | Media (6.7) | 0.16% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to improper validation of software… |