Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

439 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.93%—Cisco Prime Security Manager13/12/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.
ModificadaMedia (6.8)1.3%—Cisco Prime Optical19/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq80763.
ModificadaMedia (4.3)2.2%—Cisco Prime Data Center Network Manager29/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum86620.
ModificadaMedia (4.3)1.8%—Cisco Prime Security Manager27/3/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in dashboard-related HTML documents in Cisco Prime Security Manager (aka PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun50687.
ModificadaAlta (9)2.1%—Cisco Prime Infrastructure27/2/201417/6/2026
Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.
ModificadaMedia (4.3)2.1%—Cisco Prime Collaboration3/12/201317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCui94161.
ModificadaMedia (4.3)0.93%—Cisco Prime Network Registrar27/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in the web interface in Cisco Prime Network Registrar 8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted field, aka Bug ID CSCuh41429.
ModificadaMedia (5)1.2%—Cisco Prime Central FOR Hosted Collaboration Solution6/11/201316/6/2026
The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313.
ModificadaMedia (5)1.8%—Cisco Prime Central FOR Hosted Collaboration Solution4/11/201316/6/2026
The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345.
ModificadaMedia (4.3)0.28%—Cisco Prime Central FOR Hosted Collaboration Solution10/10/201316/6/2026
The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.
ModificadaAlta (7.8)1.7%—Cisco Prime Data Center Network Manager23/9/201316/6/2026
Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud80148.
ModificadaAlta (7.8)2.1%—Cisco Prime Data Center Network Manager23/9/201316/6/2026
DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCue77029.
ModificadaAlta (10)76%💥 ExploitCisco Prime Data Center Network Manager23/9/201316/6/2026
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by…
ModificadaAlta (7.8)1.5%—Cisco Prime Central FOR Hosted Collaboration Solution Assurance20/9/201316/6/2026
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.
ModificadaMedia (4.3)1.2%—Cisco Prime LAN Management Solution13/9/201316/6/2026
Cisco Prime LAN Management Solution (LMS) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCug77823.
ModificadaMedia (5)1.6%—Cisco Prime LAN Management SolutionCisco Security ManagerCisco Unified Operations ManagerCisco Unified Service Monitor12/9/201316/6/2026
Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to cause a denial of service (memory consumption) via…
ModificadaMedia (4.3)1.5%—Cisco Prime Network Control SystemCisco Wireless Control System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor Login pages in Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud18375.
ModificadaAlta (7.8)1.3%—Cisco Prime Central FOR Hosted Collaboration Solution Assurance25/8/201316/6/2026
Memory leak in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug ID CSCub59158.
ModificadaAlta (7.8)1.3%—Cisco Prime Central FOR Hosted Collaboration Solution Assurance25/8/201316/6/2026
Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port (1) 61615 or (2) 61616, aka Bug ID CSCtz90114.
ModificadaAlta (7.8)1.9%—Cisco Prime Central FOR Hosted Collaboration Solution Assurance25/8/201316/6/2026
Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776.
ModificadaAlta (7.8)1.3%—Cisco Prime Central FOR Hosted Collaboration Solution Assurance25/8/201316/6/2026
Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (disk consumption) via a flood of TCP packets to port 5400, leading to large error-log files, aka Bug ID CSCua42724.
ModificadaMedia (5)1.2%—Cisco Prime Central FOR Hosted Collaboration Solution26/6/201316/6/2026
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and files via a series of crafted requests, aka Bug ID CSCuh64574.
ModificadaMedia (4.3)0.94%—Cisco Prime Central FOR Hosted Collaboration Solution14/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798.
ModificadaMedia (4.3)1.5%—Cisco Prime Infrastructure31/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remote attackers to inject arbitrary web script or HTML via an SSID that is not properly handled during display of the XML windowing table, aka Bug ID CSCuf04356.
ModificadaMedia (4.3)0.94%—Cisco Prime Central FOR Hosted Collaboration Solution1/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in the OpenView web menus in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud56743.
Orbitaley — Vulnerabilidades