Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.1% | — | Cisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint Identifier (EID) to a Routing Locator (RLOC) in the map… | |
| Modificada | Alta (8.8) | 3.2% | — | Cisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An… | |
| Modificada | Crítica (9.8) | 5.2% | — | Cisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software. The vulnerability is due to insufficient input validation for the REST API of the… | |
| Modificada | Media (5.9) | 1.00% | — | Cisco IOSCisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation… | |
| Modificada | Alta (8.8) | 3.3% | — | Cisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an authenticated, remote attacker to elevate their privileges… | |
| Modificada | Media (6.5) | 0.75% | — | Cisco IOS XE | 29/9/2017 | 17/6/2026 | A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco IOS XE | 7/9/2017 | 17/6/2026 | A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to improper input… | |
| Modificada | Media (4.4) | 0.35% | — | Cisco IOS XE | 7/9/2017 | 17/6/2026 | A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the… | |
| Analizada | Alta (7.5) | 6.2% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 7/9/2017 | 17/6/2026 | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is… | |
| Modificada | Media (4.3) | 0.78% | — | Cisco IOS XE | 7/9/2017 | 17/6/2026 | A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. This could allow the attacker to pass traffic to the default VLAN… | |
| Modificada | Media (5.3) | 1.6% | — | Cisco IOSCisco IOS XE | 7/9/2017 | 17/6/2026 | A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.2) | 1.7% | — | Cisco Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+3 | 7/8/2017 | 17/6/2026 | Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an… | |
| Modificada | Media (6.5) | 0.43% | — | Cisco IOSCisco IOS XE | 7/8/2017 | 17/6/2026 | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to reset the Autonomic Control Plane (ACP) of an affected system and view ACP packets that are transferred in clear text within an affected system, an Information… | |
| Modificada | Alta (7.5) | 0.92% | — | Cisco IOS XE | 7/8/2017 | 17/6/2026 | A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked. This vulnerability affected devices that are… | |
| Analizada | Media (6.5) | 2.1% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 7/8/2017 | 17/6/2026 | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases:… | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending… | |
| Analizada | Alta (8.8) | 21% | ⚠ Explotación activa💥 PoC | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute… | |
| Modificada | Alta (8.8) | 6.6% | — | Cisco IOS XE | 17/7/2017 | 17/6/2026 | The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute… | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending… | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute… | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending… | |
| Analizada | Alta (8.8) | 45% | ⚠ Explotación activa | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute… | |
| Analizada | Alta (8.8) | 70% | ⚠ Explotación activa💥 Exploit | Cisco IOSCisco IOS XE | 17/7/2017 | 17/6/2026 | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending… | |
| Modificada | Media (6.3) | 1.7% | — | Cisco IOS XE | 20/4/2017 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when the affected software processes an SNMP read request that… | |
| Modificada | Alta (8.6) | 2.8% | — | Cisco IOSCisco IOS XE | 20/4/2017 | 17/6/2026 | Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities… |