Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Cisco IOS XECisco Cgr1000 FirmwareCisco Ir510 Wpan FirmwareCisco Ic3000 Industrial Compute Gateway Firmware+3 | 7/5/2025 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the… | |
| Analizada | Media (4.3) | 0.24% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected… | |
| Analizada | Media (5.4) | 0.33% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending… | |
| Analizada | Media (6.5) | 0.45% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending… | |
| Aplazada | Alta (7.4) | 0.25% | — | Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI | 7/5/2025 | 17/6/2026 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Analizada | Media (6.5) | 0.42% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An… | |
| Analizada | Alta (7.4) | 0.25% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory… | |
| Analizada | Crítica (10) | 27% | 💥 Exploit | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability… | |
| Analizada | Alta (8.8) | 0.91% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affected device. This vulnerability is due to insufficient input… | |
| Analizada | Alta (8.6) | 0.54% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due to improper handling of DHCP request packets. An attacker could… | |
| Analizada | Media (6) | 0.17% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN… | |
| Analizada | Alta (8.6) | 0.54% | — | Cisco IOSCisco IOS XECisco IOS XR | 7/5/2025 | 17/6/2026 | A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could… | |
| Analizada | Media (4.3) | 0.41% | — | Cisco IOS XE Sd-wan | 7/5/2025 | 17/6/2026 | A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized… | |
| Analizada | Alta (7.4) | 0.25% | — | Cisco IOS XE | 7/5/2025 | 17/6/2026 | A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.47% | — | Cisco IOS XE | 7/5/2025 | 28/9/2026 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The attacker must have valid IKEv1 VPN credentials to exploit this vulnerability. This vulnerability is due to improper… | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.76% | — | Cisco IOSCisco IOS XECisco IOS XR | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.78% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.78% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Alta (7.7) | 0.78% | — | Cisco IOSCisco IOS XE | 5/2/2025 | 17/6/2026 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. | |
| Analizada | Media (5.3) | 0.50% | — | Cisco IOS XE Sd-wan | 15/11/2024 | 17/6/2026 | This vulnerability exists because Cisco IOS Software and Cisco IOS XE Software do not support extended IPv4 ACLs for SNMP, but they do allow administrators to configure extended named IPv4 ACLs that are attached to the SNMP server configuration without a warning message. This can result in no ACL being applied to the… | |
| Analizada | Crítica (9.3) | 0.28% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is… |