Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.43% | — | Projectdiscovery Nuclei | 20/4/2026 | 17/6/2026 | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration). | |
| Analizada | Crítica (9.9) | 5.6% | — | Cisco Identity Services Engine | 15/4/2026 | 29/6/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Cisco Webex ServicesAI | 15/4/2026 | 17/6/2026 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an… | |
| Analizada | Crítica (9.9) | 6.0% | 💥 PoC | Cisco Identity Services Engine | 15/4/2026 | 8/7/2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Webex Contact Center | 15/4/2026 | 1/7/2026 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed. This vulnerability existed… | |
| Pendiente de análisis | Media (5.5) | 0.13% | — | Cisco Thousandeyes Enterprise AgentAI | 15/4/2026 | 17/6/2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system of an affected… | |
| Pendiente de análisis | Media (5.3) | 0.30% | — | Cisco AsyncosAICisco Secure WEB ApplianceAI | 15/4/2026 | 17/6/2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Identity Services Engine | 15/4/2026 | 2/7/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system. | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system. | |
| Analizada | Media (6.5) | 0.23% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to… | |
| Analizada | Media (4.7) | 0.20% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a… | |
| Analizada | Media (6.1) | 0.19% | — | Cisco Unity Connection | 15/4/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Analizada | Media (4.9) | 6.5% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper… | |
| Analizada | Crítica (9.9) | 10% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 10/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 10/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Simple IT Discussion ForumAI | 10/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The manipulation of the argument user_Id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topic-details.php. The manipulation of the argument post_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 24/7/2026 | A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 24/7/2026 | A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 9/4/2026 | 24/7/2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.1) | 0.45% | — | Simple IT Discussion ForumAI | 9/4/2026 | 24/7/2026 | A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. |