Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 0.54% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session.… | |
| Modificada | Alta (8.2) | 0.43% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the… | |
| Modificada | Crítica (9.9) | 16% | 💥 PoC | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to… | |
| Modificada | Alta (8.6) | 0.68% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 1/11/2023 | 11/8/2026 | A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation… | |
| Modificada | Media (5.4) | 0.28% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic error that occurs when an SSL/TLS… | |
| Modificada | Media (5.8) | 0.67% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an… | |
| Modificada | Media (5.8) | 0.56% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an… | |
| Modificada | Media (5.8) | 0.48% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an… | |
| Modificada | Alta (8.6) | 0.77% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain… | |
| Modificada | Media (6.1) | 0.40% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4) | 0.53% | — | Cisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly… | |
| Modificada | Media (6.5) | 0.67% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges,… | |
| Modificada | Media (6.5) | 0.51% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted… | |
| Modificada | Alta (8.6) | 0.65% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 1/11/2023 | 11/8/2026 | A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of ICMPv6 messages. An attacker could… | |
| Modificada | Media (6.1) | 0.39% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (6.1) | 0.39% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (6.1) | 0.39% | — | Cisco Secure Firewall Management Center | 1/11/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Analizada | Alta (8.8) | 4.5% | ⚠ Explotación activa | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Carrier-grade NATF5 Big-ip Ddos Hybrid Defender+16 | 26/10/2023 | 17/6/2026 | An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Carrier-grade NAT+16 | 26/10/2023 | 17/6/2026 | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Alta (7.5) | 0.50% | — | Sophos Firewall | 18/10/2023 | 17/6/2026 | A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”. | |
| Modificada | Crítica (9.8) | 66% | — | Sangfor Next-gen Application Firewall | 10/10/2023 | 17/6/2026 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell… | |
| Modificada | Crítica (9.8) | 66% | — | Sangfor Next-gen Application Firewall | 10/10/2023 | 17/6/2026 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell… | |
| Modificada | Crítica (9.8) | 18% | — | Sangfor Next-gen Application Firewall | 10/10/2023 | 17/6/2026 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header. | |
| Modificada | Media (5.3) | 0.65% | — | Sangfor Next-gen Application Firewall | 10/10/2023 | 17/6/2026 | The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |