Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.18% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilities are due path traversal and improper… | |
| En análisis | Alta (7.7) | 0.39% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker… | |
| Analizada | Alta (7.4) | 0.20% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An… | |
| Aplazada | Media (5.3) | 0.20% | — | Cisco IOS XEAICisco Catalyst 9800-clAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device. This vulnerability is due to incomplete… | |
| Aplazada | Media (6.1) | 0.29% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this… | |
| Analizada | Alta (8.1) | 0.43% | — | Cisco IOSCisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret… | |
| Analizada | Media (6.5) | 0.12% | — | Cisco IOSCisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could… | |
| Aplazada | Media (4.3) | 0.17% | — | Cisco Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless… | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Media (5.8) | 0.32% | — | Cisco Sd-wan VedgeAI | 24/9/2025 | 25/9/2026 | A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit… | |
| Aplazada | Alta (8.8) | 0.50% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this… | |
| Aplazada | Alta (7.4) | 0.61% | — | Cisco IOS XRAI | 10/9/2025 | 25/9/2026 | This vulnerability is due to how Cisco IOS XR Software processes a high, sustained rate of ARP traffic hitting the management interface. Under certain conditions, an attacker could exploit this vulnerability by sending an excessive amount of traffic to the management interface of an affected device, overwhelming its… | |
| Analizada | Media (6) | 0.10% | — | Cisco IOS XR | 10/9/2025 | 25/9/2026 | A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected… | |
| Aplazada | Media (5.3) | 0.32% | — | Cisco IOS XRAI | 10/9/2025 | 25/9/2026 | A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vulnerability exists because management interface ACLs have not been supported on… | |
| Aplazada | Alta (8.6) | 0.63% | — | Cisco Stratix 5410AICisco Stratix 5700AICisco Stratix 8000AI | 9/9/2025 | 17/6/2026 | A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can lead to remote code execution by uploading and running malicious configurations without authentication. | |
| Analizada | Alta (7.5) | 0.39% | — | Cisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 FirmwareCisco Desk Phone 9871 Firmware+13 | 3/9/2025 | 17/6/2026 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability exists because the product exposes sensitive… | |
| Analizada | Media (5.3) | 0.35% | — | Cisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 FirmwareCisco Desk Phone 9871 Firmware+13 | 3/9/2025 | 17/6/2026 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to a lack of proper authentication controls. An… | |
| Analizada | Media (5.4) | 0.22% | — | Cisco Webex Meetings | 3/9/2025 | 17/6/2026 | A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no… | |
| Analizada | Alta (8.8) | 0.18% | — | Cisco Unified Communications Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This… | |
| Analizada | Media (6.1) | 0.24% | — | Cisco Webex Meetings | 3/9/2025 | 17/6/2026 | A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed because of… | |
| Analizada | Alta (8.8) | 0.32% | — | Cisco Evolved Programmable Network Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Analizada | Media (6.5) | 0.32% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system. | |
| Analizada | Media (6.1) | 0.25% | — | Cisco Unified Communications Manager IM AND Presence Service | 3/9/2025 | 1/10/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based… | |
| Analizada | Media (5) | 0.30% | — | Cisco Nexus Dashboard | 27/8/2025 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. This vulnerability exists because of missing authorization… |