Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

8751 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.92%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the…
AnalizadaCrítica (9.8)0.87%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are…
AnalizadaAlta (7.5)0.71%💥 PoCCisco Identity Services Engine5/11/202517/6/2026
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a…
AnalizadaMedia (4.9)0.30%—Cisco Identity Services Engine5/11/202517/6/2026
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could…
AnalizadaMedia (5.4)0.21%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)3.9%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)0.21%—Cisco Identity Services Engine5/11/202517/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management…
AplazadaMedia (4.3)0.27%—WP DiscourseAI1/11/202517/6/2026
The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin unconditionally sending Discourse API credentials (Api-Key and Api-Username headers) to any host specified in a post's discourse_permalink custom field during comment…
AnalizadaMedia (6.3)0.30%—Discourse28/10/202517/6/2026
Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This…
AplazadaAlta (7.1)0.25%—Purethemes Workscout-coreAI22/10/20258/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en purethemes WorkScout-Core workscout-core permite XSS Reflejado. Este problema afecta a WorkScout-Core: desde n/a hasta < 1.7.06.
AnalizadaCrítica (9.3)2.8%⚠ Explotación activaMotex Lanscope Endpoint Manager20/10/202517/6/2026
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
AplazadaMedia (5.8)0.38%—Cisco Snort 3AI15/10/202517/6/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are parsed. An attacker could…
AnalizadaCrítica (9.1)0.48%—Cisco Snort15/10/202517/9/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. This vulnerability is due to an error in the logic of buffer handling when the MIME…
AnalizadaMedia (6.1)0.29%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/20258/10/2026
Una vulnerabilidad en la UI web de Cisco Desk Phone serie 9800, Cisco IP Phone series 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado realizar ataques XSS contra un usuario de la UI web. Esta vulnerabilidad existe porque la UI web de un…
AnalizadaAlta (7.5)0.48%—Cisco Desk Phone 9871 FirmwareCisco Desk Phone 9841 FirmwareCisco Desk Phone 9851 FirmwareCisco Desk Phone 9861 Firmware+1315/10/20258/10/2026
Una vulnerabilidad en la interfaz de usuario web de las series Cisco Desk Phone 9800, Cisco IP Phone 7800 y 8800, y Cisco Video Phone 8875 que ejecutan el software Cisco SIP podría permitir a un atacante remoto no autenticado causar una condición de DoS en un dispositivo afectado. Esta vulnerabilidad se debe a un…
AnalizadaMedia (4.9)0.36%—Cisco Telepresence Collaboration EndpointCisco Roomos15/10/20258/10/2026
Una vulnerabilidad en el componente de registro de Cisco TelePresence Collaboration Endpoint (CE) y el software Cisco RoomOS podría permitir a un atacante remoto y autenticado ver información sensible en texto claro en un sistema afectado. Para explotar esta vulnerabilidad, el atacante debe tener credenciales…
AnalizadaMedia (5.5)0.30%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites. This issue is fixed in version 3.5.1.
ModificadaMedia (4.3)0.25%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to access. By modifying the “topic_id” value in API…
AnalizadaMedia (5.4)0.20%—Discourse1/10/202517/6/2026
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AnalizadaMedia (5.4)0.21%—Cisco Cyber Vision Center1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
AplazadaMedia (5.4)0.29%—Artistscope Copysafe WEB ProtectionAI26/9/202517/6/2026
Missing Authorization vulnerability in ArtistScope CopySafe Web Protection wp-copysafe-web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CopySafe Web Protection: from n/a through <= 5.1.
AnalizadaCrítica (9)6.9%—Cisco IOS XRCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE+125/9/202511/8/2026
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or…
AnalizadaAlta (8.6)87%⚠ Explotación activa💥 ExploitCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense25/9/202511/8/2026
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS)…