Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | Cisco Prime Service Catalog | 30/10/2015 | 17/6/2026 | SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843. | |
| Modificada | Media (5) | 2.0% | — | Cisco Prime Infrastructure | 13/10/2015 | 17/6/2026 | Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830. | |
| Modificada | Media (6.8) | 1.9% | — | Cisco Prime Collaboration Assurance | 13/10/2015 | 17/6/2026 | The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and read arbitrary files via a crafted URL, aka Bug ID CSCus88380. | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Prime Collaboration Assurance | 12/10/2015 | 17/6/2026 | SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCus39887. | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Prime Collaboration Provisioning | 12/10/2015 | 17/6/2026 | SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut64074. | |
| Modificada | Alta (9) | 2.6% | — | Cisco Prime Collaboration Provisioning | 20/9/2015 | 17/6/2026 | The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111. | |
| Modificada | Alta (8.5) | 2.3% | — | Cisco Prime Collaboration Assurance | 20/9/2015 | 17/6/2026 | The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and… | |
| Modificada | Media (4) | 1.9% | — | Cisco Prime Collaboration Assurance | 20/9/2015 | 17/6/2026 | The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL, aka Bug ID CSCus62656. | |
| Modificada | Alta (9) | 2.6% | — | Cisco Prime Collaboration Assurance | 20/9/2015 | 17/6/2026 | The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652. | |
| Modificada | Alta (7.2) | 0.38% | — | Cisco Prime Network Registrar | 18/9/2015 | 17/6/2026 | Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging knowledge of the credentials, aka Bug ID CSCuw21825. | |
| Modificada | Media (6.8) | 1.00% | — | Cisco Prime Infrastructure | 25/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059. | |
| Modificada | Baja (3.5) | 1.8% | — | Cisco Prime Infrastructure | 22/8/2015 | 17/6/2026 | Cisco Prime Infrastructure (PI) 1.4(0.45) and earlier, when AAA authentication is used, allows remote authenticated users to bypass intended access restrictions via a username with a modified composition of lowercase and uppercase characters, aka Bug ID CSum59958. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 1/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818. | |
| Modificada | Media (5) | 2.4% | — | Cisco Prime Collaboration | 18/7/2015 | 17/6/2026 | Cisco Prime Collaboration Assurance 10.0 allows remote attackers to cause a denial of service (HTTP service outage) via a crafted HTTP request, aka Bug ID CSCum38844. | |
| Modificada | Media (4.3) | 1.3% | — | Cisco Prime Service Catalog | 17/6/2015 | 17/6/2026 | Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683. | |
| Modificada | Media (5) | 1.8% | — | Cisco Prime Collaboration | 17/6/2015 | 17/6/2026 | SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug IDs CSCuu29910, CSCuu29928, and CSCuu59104. | |
| Modificada | Media (6.5) | 2.1% | — | Cisco Prime Network Control System | 12/6/2015 | 17/6/2026 | The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371. | |
| Analizada | Alta (7.5) | 40% | ⚠ Explotación activa | Cisco Prime Data Center Network Manager | 3/4/2015 | 17/6/2026 | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Prime LAN Management SolutionCisco Security Manager | 27/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq54654 and CSCun18263. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Prime Security Manager | 12/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Prime Infrastructure | 12/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869. | |
| Modificada | Media (6.8) | 0.98% | — | Cisco Prime Infrastructure | 12/2/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Prime Infrastructure | 12/2/2015 | 17/6/2026 | The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444. | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Prime Service Catalog | 28/1/2015 | 17/6/2026 | The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External… | |
| Modificada | Media (4) | 1.3% | — | Cisco Prime Infrastructure | 20/12/2014 | 17/6/2026 | Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019. |