Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.6% | — | Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+1 | 20/6/2018 | 17/6/2026 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently… | |
| Modificada | Crítica (9.8) | 5.6% | — | Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+1 | 20/6/2018 | 17/6/2026 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability exists because the affected software insufficiently validates header values in… | |
| Modificada | Crítica (9.8) | 8.6% | — | Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+1 | 20/6/2018 | 17/6/2026 | A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to read sensitive memory content, create a denial of service (DoS) condition, or execute arbitrary code as root. The vulnerability exists because the affected software… | |
| Modificada | Alta (7.8) | 0.38% | — | Cisco Unified Computing System | 7/6/2018 | 17/6/2026 | A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software lacks proper input and validation checks for certain… | |
| Modificada | Crítica (9.9) | 5.0% | — | Cisco Unified Computing System Director | 19/4/2018 | 17/6/2026 | A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on any virtual machine.… | |
| Modificada | Media (6.1) | 1.7% | — | Cisco Unified Computing System Director | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… | |
| Modificada | Alta (8.8) | 2.2% | — | Cisco Unified Computing System Central Software | 8/2/2018 | 17/6/2026 | A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by posting a crafted request to… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Unified Computing System Central Software | 18/1/2018 | 17/6/2026 | A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerability is due to insufficient rate limiting protection for IPv6 ingress traffic.… | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Unified Computing System Central Software | 30/11/2017 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986. | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Unified Computing System Central Software | 30/11/2017 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf71978, CSCvf71986. | |
| Modificada | Media (6.7) | 0.68% | — | Cisco Unified Computing SystemCisco Nx-os | 30/11/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software… | |
| Modificada | Media (6) | 0.38% | — | Cisco Nx-osCisco Unified Computing SystemCisco LAN Switch Software | 30/11/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An… | |
| Modificada | Media (4.2) | 0.43% | — | Cisco Nx-osCisco Unified Computing System | 30/11/2017 | 17/6/2026 | A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation of user-supplied… | |
| Modificada | Media (6.3) | 0.94% | — | Cisco Nx-osCisco Unified Computing System | 30/11/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into a… | |
| Modificada | Media (6.7) | 0.60% | — | Cisco Nx-osCisco Unified Computing System | 30/11/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation of command arguments. An attacker could… | |
| Modificada | Media (6.7) | 0.23% | — | Cisco Nx-osCisco Unified Computing System | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this vulnerability to… | |
| Modificada | Media (4.4) | 0.33% | — | Cisco Unified Computing SystemCisco Nx-os | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch… | |
| Modificada | Media (6.7) | 0.23% | — | Cisco Nx-osCisco Unified Computing System | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this vulnerability to… | |
| Modificada | Media (6.3) | 1.1% | — | Cisco Nx-osCisco Unified Computing SystemCisco Firepower Extensible Operating System | 30/11/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 77% | — | Cisco Unified Computing System Manager FirmwareCisco Firepower 9300 Security Appliance FirmwareCisco Firepower 4100 Next-generation Firewall Firmware | 2/11/2017 | 17/6/2026 | A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the device, aka Command Injection. The vulnerability is due to… | |
| Modificada | Media (6.7) | 0.43% | — | Cisco Unified Computing System | 21/9/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands entered in the CLI, aka a Restricted Shell Break Vulnerability. An attacker could exploit this vulnerability by entering a… | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco Unified Computing System | 22/5/2017 | 17/6/2026 | A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC Software: Unified Computing System (UCS) B-Series M3 and M4… | |
| Modificada | Media (4.4) | 0.80% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known… | |
| Modificada | Alta (7.1) | 0.82% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known… |