Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.89% | 💥 PoC | Cisco IOS XR | 12/3/2025 | 17/6/2026 | A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruption that occurs when a BGP update is created with an… | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XECisco IOS XR | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Media (6.8) | 0.80% | — | Cisco IOS XR | 18/11/2024 | 17/6/2026 | A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition. This vulnerability is due to the… | |
| Analizada | Media (6.1) | 0.28% | — | Cisco IOS XR | 15/11/2024 | 17/6/2026 | A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the PPPoE process to continually crash. This vulnerability exists because the PPPoE feature does not properly handle an error condition within a… | |
| Analizada | Media (4.3) | 1.00% | — | Cisco IOS XR | 15/11/2024 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device. This vulnerability is due to a heap buffer overflow in certain Cisco Discovery… | |
| Aplazada | Media (6) | 0.18% | — | Cisco Network Convergence System 4000 SeriesAICisco IOS XRAI | 15/11/2024 | 17/6/2026 | A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in the TL1 process. This vulnerability is due to TL1 not freeing memory under some conditions. An attacker could exploit this vulnerability by connecting to… | |
| Analizada | Media (5.5) | 0.14% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software.… | |
| Analizada | Alta (7.2) | 1.1% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform… | |
| Analizada | Alta (7.4) | 0.24% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of… | |
| Analizada | Alta (7.8) | 0.21% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker… | |
| Analizada | Media (5.3) | 0.44% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751. This vulnerability is due to a lack of proper error validation of ingress XML packets. An attacker could exploit this… | |
| Analizada | Alta (8.8) | 0.58% | — | Cisco IOS XRCisco Network Services OrchestratorCisco Small Business RV Series Router Firmware | 11/9/2024 | 17/6/2026 | This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications… | |
| Analizada | Media (5.5) | 0.14% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device. This vulnerability is due to incorrect validation of the arguments that are… | |
| Analizada | Alta (7.4) | 0.24% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is… | |
| Analizada | Alta (7.5) | 0.60% | — | Cisco IOS XR | 11/9/2024 | 17/6/2026 | A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 code does not properly handle packet memory. An attacker could exploit… | |
| Analizada | Media (6.7) | 0.19% | — | Cisco IOS XR | 10/7/2024 | 17/6/2026 | A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected… | |
| Analizada | Alta (7.4) | 0.34% | — | Cisco IOS XR | 13/3/2024 | 17/6/2026 | A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper… | |
| Analizada | Media (5.8) | 0.49% | — | Cisco IOS XR | 13/3/2024 | 17/6/2026 | A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignment of lookup keys to internal interface contexts. An attacker… | |
| Analizada | Alta (7.8) | 0.19% | — | Cisco IOS XR | 13/3/2024 | 17/6/2026 | A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation… | |
| Analizada | Media (4.3) | 0.25% | — | Cisco IOS XR | 13/3/2024 | 17/6/2026 | A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected device. This vulnerability is due to incorrect UDP forwarding… | |
| Aplazada | Alta (7.4) | 0.33% | — | Cisco IOS XRAI | 13/3/2024 | 17/6/2026 | A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network processor to reset, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of specific Ethernet frames that are… | |
| Aplazada | Media (5.8) | 0.52% | — | Cisco IOS XRAI | 13/3/2024 | 17/6/2026 | A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignment of lookup keys to internal interface contexts. An attacker could… | |
| Aplazada | Media (5.3) | 0.64% | — | Cisco IOS XRAI | 13/3/2024 | 17/6/2026 | A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because certain DHCPv4 messages are improperly validated when they… | |
| Aplazada | Media (6.5) | 0.15% | — | Cisco IOS XRAI | 13/3/2024 | 17/6/2026 | A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or overwrite files in a system directory, which could lead to a denial of service (DoS) condition. The attacker would require valid user credentials to perform this attack.… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |