Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.93% | — | Cisco Wireless LAN Controller Software | 7/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCun95178. | |
| Modificada | Media (6.1) | 0.63% | — | Cisco Wireless LAN Controller Software | 28/3/2015 | 17/6/2026 | The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 6/3/2014 | 17/6/2026 | Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCuf80681. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 6/3/2014 | 17/6/2026 | Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929. | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 6/3/2014 | 17/6/2026 | The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 MLDv2 packet, aka Bug ID CSCuh74233. | |
| Modificada | Alta (7.1) | 1.2% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 6/3/2014 | 17/6/2026 | The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a crafted field in an IGMPv3 message, aka Bug ID CSCuh33240. | |
| Modificada | Alta (10) | 2.0% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 6/3/2014 | 17/6/2026 | Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by connecting to an Aironet access point on which this server had been disabled… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Wireless LAN Controller Software | 6/3/2014 | 17/6/2026 | Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate memory, which allows remote attackers to cause a denial of service (reboot) by sending WebAuth login requests at a high rate, aka Bug ID CSCuf52361. | |
| Modificada | Media (6.1) | 0.57% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 28/2/2013 | 16/6/2026 | The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, aka Bug ID CSCue04153. | |
| Modificada | Alta (9) | 3.1% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+3 | 24/1/2013 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote authenticated users to bypass wireless-management settings and read or modify the device configuration via an SNMP request, aka Bug ID CSCua60653. | |
| Modificada | Alta (9) | 3.7% | — | Cisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN ControllerCisco 4100 Wireless LAN Controller+5 | 24/1/2013 | 16/6/2026 | The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP User-Agent header, aka Bug ID CSCuc15636. | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+5 | 24/1/2013 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (Access Point reload) via crafted SIP packets, aka Bug ID CSCts87659. | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+5 | 24/1/2013 | 16/6/2026 | The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device reload) via crafted IP packets, aka Bug ID CSCtx80743. | |
| Modificada | Media (4.3) | 3.7% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+5 | 19/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992. | |
| Modificada | Media (6.8) | 1.8% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+5 | 19/12/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via… | |
| Modificada | Media (6.3) | 5.5% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2500 Wireless LAN Controller+5 | 19/12/2012 | 16/6/2026 | screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209. | |
| Modificada | Alta (9.3) | 1.8% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2106 Wireless LAN Controller+9 | 1/3/2012 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2106 Wireless LAN Controller+9 | 1/3/2012 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when WebAuth is enabled, allow remote attackers to cause a denial of service (device reload) via a sequence of (1) HTTP or (2) HTTPS packets, aka Bug ID CSCtt47435. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2106 Wireless LAN Controller+9 | 1/3/2012 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (device reload) via a sequence of IPv6 packets, aka Bug ID CSCtt07949. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Wireless LAN Controller SoftwareCisco 2000 Wireless LAN ControllerCisco 2100 Wireless LAN ControllerCisco 2106 Wireless LAN Controller+9 | 1/3/2012 | 16/6/2026 | The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997. | |
| Modificada | Alta (7.8) | 10% | — | Cisco Wireless LAN Controller Software | 3/5/2011 | 16/6/2026 | Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID CSCth74426. | |
| Modificada | Media (5) | 1.1% | — | Cisco Wireless LAN Controller Software | 10/9/2010 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-0575. | |
| Modificada | Alta (9) | 1.5% | — | Cisco Wireless LAN Controller Software | 10/9/2010 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-2843. | |
| Modificada | Alta (9) | 1.5% | — | Cisco Wireless LAN Controller Software | 10/9/2010 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-3033. | |
| Modificada | Alta (9) | 1.5% | — | Cisco Wireless LAN Controller Software | 10/9/2010 | 16/6/2026 | Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2843 and CVE-2010-3033. |