Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain… | |
| Modificada | Media (5.1) | 0.36% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS template contexts. Attackers can inject malicious expressions that are compiled and executed by the AngularJS 1.5.2… | |
| Analizada | Media (5.3) | 0.17% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment… | |
| Analizada | Alta (8.7) | 0.52% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood… | |
| Aplazada | Alta (8.8) | 0.32% | — | Iscripts ReservelogicAI | 12/3/2026 | 17/6/2026 | iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information. | |
| Pendiente de análisis | Media (6.8) | 0.32% | — | Cisco IOS XRAICisco Network Convergence System 5500AICisco Network Convergence System 5700AI | 11/3/2026 | 17/6/2026 | A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthenticated, remote… | |
| Analizada | Media (6.1) | 0.21% | — | Cisco Unified Contact Center Express | 11/3/2026 | 8/7/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected… | |
| En análisis | Media (6.1) | 0.21% | — | Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI+1 | 11/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote… | |
| Analizada | Alta (7.4) | 0.16% | — | Cisco IOS XR | 11/3/2026 | 8/7/2026 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. | |
| Analizada | Alta (8.8) | 0.14% | — | Cisco IOS XR | 11/3/2026 | 1/7/2026 | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code.… | |
| Analizada | Alta (8.8) | 0.17% | — | Cisco IOS XR | 11/3/2026 | 1/7/2026 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker… | |
| Analizada | Media (6.5) | 0.10% | — | Cisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker with a low-privileged… | |
| Analizada | Media (6.8) | 0.17% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This… | |
| Analizada | Media (5.7) | 0.20% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This… | |
| Analizada | Media (6.5) | 0.16% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Media (6.5) | 0.20% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition when OSPF canonicalization debug is enabled by using the command debug ip ospf… | |
| Analizada | Media (4.3) | 0.21% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. This vulnerability… | |
| Analizada | Media (5.7) | 0.26% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to… | |
| Analizada | Media (6.7) | 0.34% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid… | |
| Analizada | Media (6.1) | 0.24% | — | Cisco Webex | 4/3/2026 | 17/6/2026 | A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed. This vulnerability was due to improper filtering of user-supplied input. Prior to this vulnerability being… | |
| Analizada | Crítica (10) | 43% | ⚠ Explotación activa💥 PoC | Cisco Secure Firewall Management Center | 4/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.… | |
| Analizada | Media (5.3) | 0.33% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS)… | |
| Analizada | Alta (7.7) | 0.32% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS)… | |
| Analizada | Alta (8.6) | 0.36% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition to new Remote Access… | |
| Analizada | Media (6.1) | 0.27% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based… |