Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1724 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.2%—Sophos XG Firewall Firmware1/12/202217/6/2026
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (7.2)1.8%—Sophos XG Firewall Firmware1/12/202217/6/2026
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
ModificadaAlta (8.8)0.31%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall22/11/202217/6/2026
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.
ModificadaMedia (5.3)0.84%—Cisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a lack of error-checking when SIP bidirectional flows are being inspected by Snort 3. An…
ModificadaMedia (4.9)0.74%—Cisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because access to HTTPS endpoints is not properly restricted on an affected…
ModificadaAlta (7.5)0.93%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is…
ModificadaAlta (7.5)0.93%—Cisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory handling error that occurs…
ModificadaMedia (5.8)0.95%—Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Meraki MX Security Appliance Firmware15/11/202211/8/2026
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to…
ModificadaMedia (5.3)0.70%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with…
ModificadaMedia (5.3)0.69%—Cisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses SSL decryption…
ModificadaMedia (4.3)0.56%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (6.7)0.29%—Cisco Secure Firewall Threat DefenseCisco Firepower Extensible Operating System15/11/202211/8/2026
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could…
ModificadaMedia (4.8)0.50%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (5.8)0.73%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the…
ModificadaMedia (6.5)0.53%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco Firepower Services Software FOR ASA15/11/202211/8/2026
A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a…
ModificadaAlta (8.8)0.89%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API…
ModificadaAlta (7.2)0.88%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API…
ModificadaMedia (6.5)0.84%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to…
ModificadaMedia (6.5)0.82%—Cisco Secure Firewall Threat DefenseCisco Umbrella Virtual ApplianceCisco Cyber Vision15/11/202211/8/2026
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to…
ModificadaAlta (7.5)0.90%—Cisco Firepower Services Software FOR ASACisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated,…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaAlta (7.5)0.93%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense15/11/202211/8/2026
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when…