Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Cloud Services Appliance8/12/20214/8/2026
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
ModificadaAlta (7.5)3.2%💥 PoCOwasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+27/12/202117/6/2026
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for…
ModificadaMedia (5.5)0.67%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.
ModificadaMedia (5.5)0.23%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
ModificadaMedia (6.7)0.26%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.
ModificadaMedia (5.5)0.22%—IBM MQ Appliance30/11/202117/6/2026
IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042
ModificadaMedia (6.5)0.94%—IBM MQ Appliance8/11/202117/6/2026
IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing message properties. IBM X-Force ID: 205203.
ModificadaMedia (5.3)11%—ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+1127/10/202117/6/2026
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause…
ModificadaMedia (6.5)1.0%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x FirmwareCisco ASA 5505 Firmware+627/10/202111/8/2026
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is…
ModificadaAlta (7.5)1.4%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS…
ModificadaAlta (7.5)1.5%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incoming SSL/TLS…
ModificadaMedia (5.3)0.94%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x FirmwareCisco ASA 5505 Firmware+627/10/202111/8/2026
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to query SNMP data. This vulnerability is due to ineffective…
ModificadaAlta (8.6)0.59%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service (DoS) vulnerability. This vulnerability is…
ModificadaAlta (7.5)1.4%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x FirmwareCisco ASA 5505 Firmware+627/10/202111/8/2026
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when…
ModificadaMedia (5.3)1.1%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a…
ModificadaMedia (5.3)1.1%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the ALG and open unauthorized connections with a…
ModificadaMedia (5.3)1.0%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x Firmware+727/10/202111/8/2026
A vulnerability in the identity-based firewall (IDFW) rule processing feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass security protections. This vulnerability is due to improper handling of network…
ModificadaAlta (7.5)1.6%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco ASA 5512-x FirmwareCisco ASA 5505 Firmware+627/10/202111/8/2026
A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is…
ModificadaAlta (7.5)1.4%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an…
ModificadaMedia (6.1)0.62%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (4.8)0.48%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.1)2.0%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input…
ModificadaMedia (6)0.22%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user…
ModificadaAlta (7.8)0.27%—Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center27/10/202111/8/2026
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.