Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.74% | — | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. | |
| Analizada | Alta (7.5) | 7.1% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 25/2/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Analizada | Alta (7.8) | 0.31% | — | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by… | |
| Analizada | Media (5.4) | 25% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to… | |
| Aplazada | Crítica (9.9) | 0.90% | — | CatalystAI | 10/2/2026 | 17/6/2026 | Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with template.create or template.update… | |
| Aplazada | Media (4.7) | 0.25% | — | Cisco Catalyst Center Virtual ApplianceAI | 13/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Catalyst Center | 13/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Analizada | Alta (8.8) | 0.36% | — | Cisco Catalyst Center | 13/11/2025 | 17/6/2026 | A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user. This vulnerability is due to insufficient validation of user-supplied input in REST API request parameters. An attacker could exploit this… | |
| Analizada | Media (4.3) | 0.27% | — | Cisco Catalyst Center | 13/11/2025 | 17/6/2026 | A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should require Administrator privileges. The attacker would need valid read-only user credentials. This vulnerability is due to improper role-based access control (RBAC). An attacker could exploit this… | |
| Aplazada | Alta (8.8) | 0.51% | — | Cisco Catalyst Center Virtual ApplianceAI | 13/11/2025 | 17/6/2026 | A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted HTTP… | |
| Aplazada | Media (5.3) | 0.34% | — | Cisco IOS XEAICisco Catalyst 9500xAICisco Catalyst 9600xAI | 24/9/2025 | 25/9/2026 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. This vulnerability is due to the flooding of traffic from an unlearned MAC address… | |
| Aplazada | Media (5.3) | 0.20% | — | Cisco IOS XEAICisco Catalyst 9800-clAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device. This vulnerability is due to incomplete… | |
| Aplazada | Alta (8.2) | 0.28% | — | Fortra FilecatalystAI | 19/8/2025 | 17/6/2026 | Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page. | |
| Aplazada | Alta (8.6) | 0.43% | — | Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI | 11/8/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.5) | 0.26% | — | Catalyst Plugin SessionAI | 17/7/2025 | 17/6/2026 | Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Catalyst context. This information is of low entropy. The PID will come from a small… | |
| Aplazada | Media (5.3) | 0.46% | — | Moodle Catalyst User KEY Authentication PluginAI | 10/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be… | |
| Analizada | Media (4.7) | 0.28% | — | Cisco Catalyst Center | 7/5/2025 | 17/6/2026 | A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to read and modify data in a repository that belongs to an internal service of an affected device. This vulnerability is due to insufficient enforcement of access control on HTTP requests. An attacker… | |
| Analizada | Media (4.3) | 0.34% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper sanitization of input to the web interface. An attacker could exploit… | |
| Analizada | Media (5.5) | 0.17% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker must have valid read-only credentials with CLI access on the… | |
| Analizada | Alta (7.3) | 0.41% | — | Cisco Catalyst Center | 7/5/2025 | 17/6/2026 | A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this… | |
| Analizada | Media (6.5) | 1.3% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this… | |
| Analizada | Media (5.9) | 0.29% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation of certificates that are used by the Smart Licensing feature.… | |
| Analizada | Media (5.4) | 0.33% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | This vulnerability is due to improper sanitization of user input to the web-based management interface. An attacker could exploit this vulnerability by submitting a malicious script through the interface. A successful exploit could allow the attacker to conduct a stored XSS attack on the affected system. | |
| Analizada | Alta (7.8) | 0.15% | — | Cisco Catalyst Sd-wan Manager | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to gain privileges of the root user on the underlying operating system. This vulnerability is due to insufficient input validation. An authenticated attacker with read-only… |