Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Cisco Content Services Switch 11500Cisco ACE 47106/7/201016/6/2026
The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and…
ModificadaAlta (7.5)1.8%—Cisco Content Services Switch 11500Cisco ACE 47106/7/201016/6/2026
The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended…
ModificadaAlta (7.5)1.7%—Cisco Content Services Switch 115006/7/201016/6/2026
The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted header data, as demonstrated by a ClientCert-Subject-CN…
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.8(1)S5 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsz13590.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (TCP socket exhaustion) via unknown vectors, aka Bug ID CSCsk13561.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsk04588.
ModificadaAlta (7.8)1.8%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed Contact header, aka Bug ID CSCsj98521.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S11 and 9.7(3)P before 9.7(3)P11 allows remote attackers to cause a denial of service (device crash) via a long message, aka Bug ID CSCsk44115.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via unknown SIP traffic, as demonstrated by "SIP testing," aka Bug ID CSCsk38165.
ModificadaAlta (7.8)1.8%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via a malformed session attribute, aka Bug ID CSCsk40030.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsk32606.
ModificadaAlta (7.8)2.5%—Cisco PGW 2200 Softswitch14/5/201016/6/2026
The MGCP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsl39126.
ModificadaMedia (4.3)5.6%💥 ExploitIpswitch WS FTP21/4/201016/6/2026
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.
ModificadaMedia (4.3)2.0%💥 ExploitAPC Network Management CardAPC Switched Rack PDU28/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username…
ModificadaMedia (6.8)0.67%—APC Network Management CardAPC Switched Rack PDU28/12/200916/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to hijack the authentication of (1) administrator or (2) device users for requests…
ModificadaAlta (10)2.1%—Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM SwitchAten Pn9108 Power Over THE NET27/5/200916/6/2026
The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt https sessions by extracting this key from their own switch and…
ModificadaAlta (7.6)1.7%—Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch27/5/200916/6/2026
The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes it easier for man-in-the-middle attackers to perform mouse operations on machines connected to the switch by injecting network traffic; and do not (2) set the secure flag…
ModificadaAlta (10)3.2%—Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch27/5/200916/6/2026
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cryptography for a symmetric session-key negotiation, which makes it easier for remote attackers to (a) decrypt network traffic, or (b)…
ModificadaAlta (10)1.1%—Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch27/5/200916/6/2026
The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded AES encryption key, which makes it easier for man-in-the-middle attackers to (1) execute arbitrary Java code, or (2) gain access to machines connected to the switch, by…
ModificadaAlta (9)24%💥 ExploitIpswitch Imail27/1/200916/6/2026
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow…
ModificadaMedia (5)4.5%—Ipswitch WS FTP19/12/200816/6/2026
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
ModificadaMedia (5)13%💥 ExploitIpswitch WS FTP19/12/200816/6/2026
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.
ModificadaAlta (7.1)32%💥 PoCBSDBsdi BSD OSCisco IOSDragonflybsd+1520/10/200816/6/2026
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as…
ModificadaAlta (10)15%💥 ExploitIpswitch WS FTP Home27/8/200816/6/2026
Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response."
ModificadaAlta (9.3)14%💥 ExploitIpswitch WS FTP HomeIpswitch WS FTP PRO20/8/200816/6/2026
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).