Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9) | 6.9% | — | Cisco IOS XRCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE+1 | 25/9/2025 | 11/8/2026 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or… | |
| Analizada | Alta (7.7) | 39% | ⚠ Explotación activa💥 PoC | Cisco IOS XE Sd-wanCisco IOS XECisco IOS | 24/9/2025 | 25/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco… | |
| Analizada | Media (6.7) | 0.16% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to… | |
| Aplazada | Media (5.3) | 0.34% | — | Cisco IOS XEAICisco Catalyst 9500xAICisco Catalyst 9600xAI | 24/9/2025 | 25/9/2026 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. This vulnerability is due to the flooding of traffic from an unlearned MAC address… | |
| Analizada | Alta (8.6) | 0.44% | — | Cisco IOS XE | 24/9/2025 | 28/9/2026 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition. This vulnerability is due to improper handling of malformed Control and Provisioning… | |
| Aplazada | Media (6.7) | 0.16% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to improper validation of software… | |
| Analizada | Media (6.7) | 0.18% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilities are due path traversal and improper… | |
| En análisis | Alta (7.7) | 0.39% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker… | |
| Analizada | Alta (7.4) | 0.20% | — | Cisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An… | |
| Aplazada | Media (5.3) | 0.20% | — | Cisco IOS XEAICisco Catalyst 9800-clAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device. This vulnerability is due to incomplete… | |
| Aplazada | Media (6.1) | 0.29% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this… | |
| Analizada | Alta (8.1) | 0.43% | — | Cisco IOSCisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret… | |
| Analizada | Media (6.5) | 0.12% | — | Cisco IOSCisco IOS XE | 24/9/2025 | 25/9/2026 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could… | |
| Aplazada | Alta (8.8) | 0.50% | — | Cisco IOS XEAI | 24/9/2025 | 25/9/2026 | A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this… | |
| Aplazada | Alta (8.6) | 0.47% | — | Cisco IOSAICisco IOS XEAICisco Secure Firewall ASAAICisco Secure FTDAI | 14/8/2025 | 17/6/2026 | A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is due to the improper processing of IKEv2 packets. An… | |
| Aplazada | Alta (8.6) | 0.62% | — | Cisco IOSAICisco IOS XEAICisco ASAAICisco FTDAI | 14/8/2025 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of… | |
| Aplazada | Media (5.8) | 0.71% | — | Cisco IOSAICisco IOS XEAICisco ASAAICisco FTDAI | 14/8/2025 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of… | |
| Analizada | Crítica (9.1) | 0.52% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by… | |
| Analizada | Media (4.3) | 0.34% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner API call behavior causes results to be… | |
| Analizada | Alta (7.4) | 0.23% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they… | |
| Analizada | Media (6.7) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An… | |
| Analizada | Alta (8.2) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An… | |
| Analizada | Alta (8.2) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An… | |
| Analizada | Alta (8.2) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An… | |
| Analizada | Alta (8.2) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An… |