Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

7116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.61%—Cisco Secure Firewall ASAAICisco Secure FTDAI14/8/202517/6/2026
A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to improper validation of user-supplied input on an…
AplazadaAlta (8.6)0.62%—Cisco IOSAICisco IOS XEAICisco ASAAICisco FTDAI14/8/202517/6/2026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of…
AplazadaMedia (6)0.15%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the…
AplazadaMedia (6)0.15%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the…
AnalizadaMedia (6.1)0.29%—Cisco Secure Firewall Management Center14/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by…
AplazadaMedia (5.8)0.71%—Cisco IOSAICisco IOS XEAICisco ASAAICisco FTDAI14/8/202517/6/2026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of…
AplazadaAlta (8.6)0.64%—Cisco Secure Firewall ASAAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to…
AplazadaMedia (6)0.17%—Cisco Secure Firewall Management CenterAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for…
AplazadaMedia (5.3)0.38%—Cisco Secure Firewall ASAAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should have been blocked to a loopback…
AnalizadaMedia (4.9)0.45%—Cisco Secure Firewall Management Center14/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this…
AplazadaAlta (8.6)0.72%—Cisco Secure Firewall Threat DefenseAICisco Snort 3AI14/8/202517/6/2026
A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of traffic…
AnalizadaAlta (8.5)0.46%—Cisco Secure Firewall Management Center14/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability is due to improper validation of user-supplied data. An attacker could…
AplazadaAlta (8.6)0.64%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
This vulnerability is due to an infinite loop condition that occurs when a Cisco Secure ASA or Cisco Secure FTD device processes DNS packets with DNS inspection enabled and the device is configured for NAT44, NAT64, or NAT46. An attacker could exploit this vulnerability by sending crafted DNS packets that match a…
AplazadaMedia (4.3)0.20%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to exhaust available memory. This vulnerability is due to improper validation of incoming DHCP…
AplazadaAlta (8.6)0.42%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI14/8/202517/6/2026
A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This…
AplazadaAlta (8.6)0.78%—Cisco Secure Firewall ASA SoftwareAICisco Secure FTD SoftwareAI14/8/202517/6/2026
A vulnerability in the management and VPN web servers of the Remote Access SSL VPN feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly stop responding, resulting in a DoS condition. This vulnerability is due to…
AnalizadaAlta (7.7)0.66%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software14/8/202511/8/2026
A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are…
AnalizadaMedia (5.8)0.71%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software14/8/202518/9/2026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This…
AplazadaMedia (4.3)0.40%—Cisco ISEAI6/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by…
AplazadaMedia (5.4)0.22%—Cisco ISEAICisco Ise-picAI6/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an…
AplazadaMedia (5.4)0.10%—Cisco Webex MeetingsAI6/8/202517/6/2026
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco…
AnalizadaCrítica (10)68%⚠ Explotación activaCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation…
AnalizadaMedia (5.3)0.37%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express16/7/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker…
AnalizadaMedia (4.1)0.42%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured…
AnalizadaAlta (7.2)19%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this…