Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 10% | ⚠ Explotación activa | Cisco Anyconnect Secure Mobility Client | 17/8/2020 | 12/8/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The… | |
| Analizada | Media (6.5) | 28% | ⚠ Explotación activa | Cisco Anyconnect Secure Mobility Client | 19/2/2020 | 12/8/2026 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could… | |
| Modificada | Media (5.5) | 0.29% | — | Infinixmobility Note 5 Firmware | 14/11/2019 | 17/6/2026 | The Infinix Note 5 Android device with a build fingerprint of Infinix/H633B/Infinix-X604_sprout:8.1.0/O11019/L-IN-180206V64:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Media (5.5) | 0.29% | — | Infinixmobility Note 5 Firmware | 14/11/2019 | 17/6/2026 | The Infinix Note 5 Android device with a build fingerprint of Infinix/H633IJL/Infinix-X604_sprout:8.1.0/O11019/IJL-180531V181:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a… | |
| Modificada | Media (5.5) | 0.29% | — | Infinixmobility Note 5 Firmware | 14/11/2019 | 17/6/2026 | The Infinix Note 5 Android device with a build fingerprint of Infinix/H632C/Infinix-X605_sprout:8.1.0/O11019/CE-180914V59:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Anyconnect Secure Mobility Client | 16/5/2019 | 17/6/2026 | A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this… | |
| Modificada | Media (4.7) | 0.48% | — | Blackberry Enterprise Mobility Server | 19/9/2018 | 17/6/2026 | A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account. | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Mobility Services Engine 3365 FirmwareCisco Mobility Services Engine 3355 FirmwareCisco Mobility Services Engine 3310 Firmware | 18/7/2018 | 17/6/2026 | A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5.5) | 0.29% | — | Cisco Mobility Services Engine 3365 FirmwareCisco Mobility Services Engine 3355 FirmwareCisco Mobility Services Engine 3310 Firmware | 18/7/2018 | 17/6/2026 | A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readable). An attacker could exploit this vulnerability by logging in to the CLI. An exploit could allow… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco Mobility Services EngineCisco Policy Suite | 18/7/2018 | 17/6/2026 | A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by directly… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco Mobility Services EngineCisco Policy Suite | 18/7/2018 | 17/6/2026 | A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by accessing the Policy Builder interface. A… | |
| Modificada | Crítica (9.8) | 3.7% | — | Cisco Mobility Services EngineCisco Policy Suite | 18/7/2018 | 17/6/2026 | A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the root… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco Mobility Services Engine | 18/7/2018 | 17/6/2026 | A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by connecting directly to the Policy… | |
| Modificada | Alta (7.5) | 0.44% | — | Mitel Shortel Mobility Client | 13/7/2018 | 17/6/2026 | On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to obtain sensitive account information such as login credentials. | |
| Modificada | Media (5.5) | 0.39% | — | Cisco Anyconnect Secure Mobility Client | 21/6/2018 | 17/6/2026 | A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to improper validation of… | |
| Modificada | Media (4.8) | 0.98% | — | Cisco Anyconnect Secure Mobility Client | 7/6/2018 | 17/6/2026 | A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration… | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Mobility Express Software | 2/5/2018 | 17/6/2026 | A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The… | |
| Modificada | Media (6.5) | 3.4% | — | Cisco Anyconnect Secure Mobility ClientCisco Adaptive Security Appliance Software | 19/4/2018 | 17/6/2026 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated,… | |
| Modificada | Media (5.9) | 0.88% | — | Samsung Knox Enterprise Mobility ManagementSamsung Knox Identity Access Management | 20/2/2018 | 17/6/2026 | In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain… | |
| Modificada | Media (5.3) | 1.4% | — | Cisco Mobility Services Engine | 8/2/2018 | 17/6/2026 | A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component returns different authentication failure messages based on the… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco Mobility Services Engine | 8/2/2018 | 17/6/2026 | A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however, the attacker must provide a valid username. The vulnerability is due to incorrect RADIUS user credential validation. An… | |
| Modificada | Media (4.4) | 0.41% | — | Cisco Anyconnect Secure Mobility Client | 18/1/2018 | 17/6/2026 | A vulnerability in the Profile Editor of the Cisco AnyConnect Secure Mobility Client could allow an unauthenticated, local attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of the XML External Entity (XXE) entries when parsing an XML… | |
| Modificada | Media (6.5) | 0.35% | — | Cisco Anyconnect Secure Mobility Client | 5/10/2017 | 17/6/2026 | A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insufficient NAM policy enforcement. An attacker could exploit this… | |
| Modificada | Media (4.8) | 3.8% | — | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Anyconnect Secure Mobility Client | 17/8/2017 | 17/6/2026 | The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerability is due to insufficient input validation of some… |