Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.27%—IBM QradarAI18/9/202618/9/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Pendiente de análisisAlta (8.2)0.46%—Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could…
Pendiente de análisisAlta (8.8)0.20%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.1)0.28%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.4)0.26%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.8)0.32%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisCrítica (9.9)0.30%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Pendiente de análisisAlta (8.6)0.55%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAICisco Secure Firewall 3100 SeriesAICisco Secure Firewall 4200 SeriesAI16/9/202618/9/2026
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service…
Pendiente de análisisAlta (8.6)0.40%—Cisco Secure Firewall Adaptive Security Appliance ASA SoftwareAICisco Secure Firewall Threat Defense FTD SoftwareAI16/9/202618/9/2026
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload…
Pendiente de análisisMedia (6.8)0.34%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI16/9/202618/9/2026
A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to…
Pendiente de análisisAlta (7.4)0.17%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI16/9/202618/9/2026
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This…
Pendiente de análisisAlta (8.6)0.40%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI16/9/202618/9/2026
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a…
Pendiente de análisisMedia (5.3)0.49%—Cisco Adaptive Security ApplianceAICisco Threat DefenseAI16/9/202618/9/2026
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability…
Pendiente de análisisMedia (5.8)0.41%—Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI16/9/202618/9/2026
A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability…
Pendiente de análisisCrítica (9.9)0.34%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
The vulnerabilities tracked by CVE-2026-20330 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
Pendiente de análisisCrítica (9.9)0.45%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
The vulnerabilities tracked by CVE-2026-20329 are related to issues concerning improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Pendiente de análisisCrítica (9.6)0.23%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
The vulnerabilities tracked by CVE-2026-20331 are related to the failure of protection mechanisms issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-693.
AplazadaAlta (8.8)0.48%—ScadaltsAI16/9/202618/9/2026
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which…
AplazadaMedia (6.5)0.36%—ScadaltsAI16/9/202618/9/2026
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQL ORDER BY clause without any sanitization or parameterization. This allows…
AplazadaAlta (8.8)0.84%—ScadaltsAI16/9/202618/9/2026
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on…
AplazadaCrítica (9.3)0.78%—Myscada Mypro ManagerAI15/9/202618/9/2026
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
AplazadaAlta (8.5)0.39%—FrontmcpAIFrontmcp Mcp-from-openapiAI@frontmcp/adaptersAI15/9/202630/9/2026
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution…
AplazadaAlta (7.1)0.30%—LaradashboardAI14/9/202623/9/2026
laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store,…
AplazadaAlta (8.6)0.82%—LaradashboardAI14/9/202623/9/2026
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation,…
AplazadaMedia (5.1)0.24%—LaradashboardAI14/9/202623/9/2026
LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application…
Orbitaley — Vulnerabilidades