Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.35% | — | Cisco Application Policy Infrastructure Controller | 3/5/2019 | 17/6/2026 | A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerability is due to insufficient input validation for certain command strings issued on… | |
| Modificada | Media (4.6) | 0.20% | — | Cisco Application Policy Infrastructure Controller | 3/5/2019 | 17/6/2026 | A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption keys stored on local partitions in the… | |
| Modificada | Media (6.5) | 0.61% | — | Cisco Application Policy Infrastructure Controller | 11/3/2019 | 17/6/2026 | A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control mechanisms for IPv6 link-local connectivity… | |
| Modificada | Alta (7.8) | 0.39% | — | Cisco Nx-osCisco Application Policy Infrastructure Controller Software | 6/3/2019 | 17/6/2026 | A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device. The vulnerability is due to a misconfiguration of certain sudoers files for the bashroot… | |
| Modificada | Alta (8.8) | 6.1% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 15/8/2018 | 17/6/2026 | A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of user-supplied data. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 16/7/2018 | 17/6/2026 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affected software. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Application Policy Infrastructure Controller | 30/11/2017 | 17/6/2026 | A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system. The vulnerability is… | |
| Modificada | Alta (8.8) | 0.78% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 2/11/2017 | 17/6/2026 | A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device. The vulnerability is due to an incorrect… | |
| Modificada | Alta (7.8) | 0.42% | — | Cisco Application Policy Infrastructure Controller | 17/8/2017 | 17/6/2026 | A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges. The vulnerability is due to a custom executable system file that was built… | |
| Modificada | Alta (7.1) | 1.2% | — | Cisco Application Policy Infrastructure Controller | 17/8/2017 | 17/6/2026 | A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileges of the last user to log in, regardless of whether those privileges are higher or lower than what… | |
| Modificada | Media (6.5) | 0.72% | — | Cisco Application Policy Infrastructure ControllerCisco Nx-os | 19/11/2016 | 17/6/2026 | A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and… | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Application Policy Infrastructure Controller | 24/9/2016 | 17/6/2026 | The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496. | |
| Modificada | Alta (8.8) | 2.7% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 18/8/2016 | 17/6/2026 | The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507. | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Application Infrastructure ControllerCisco Application Policy Infrastructure Controller Firmware | 10/6/2016 | 17/6/2026 | The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCuz72347. | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 28/4/2016 | 17/6/2026 | The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 9/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 7/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Application Policy Infrastructure Controller Enterprise Module | 26/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CSCuw47238. | |
| Modificada | Alta (7.2) | 0.38% | — | Cisco Application Policy Infrastructure Controller | 18/12/2015 | 17/6/2026 | The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985. | |
| Modificada | Media (4.6) | 0.36% | — | Cisco Application Policy Infrastructure Controller | 16/10/2015 | 17/6/2026 | Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076. | |
| Modificada | Alta (9) | 2.2% | — | Cisco Application Policy Infrastructure Controller (apic)Cisco Nx-os | 24/7/2015 | 17/6/2026 | Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root… |