Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 42% | — | Fortra Filecatalyst Workflow | 13/3/2024 | 17/6/2026 | A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be… | |
| Modificada | Media (6.5) | 0.53% | — | Cisco Catalyst Sd-wan Manager | 18/10/2023 | 17/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to… | |
| Modificada | Media (4.7) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware | 27/9/2023 | 17/6/2026 | This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A… | |
| Modificada | Alta (7.5) | 1.0% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 27/9/2023 | 17/6/2026 | A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected. This… | |
| Modificada | Media (5.5) | 0.17% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 27/9/2023 | 17/6/2026 | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router device. This vulnerability is due to improper access control… | |
| Modificada | Crítica (9.8) | 1.1% | — | Cisco Catalyst Sd-wan Manager | 27/9/2023 | 17/6/2026 | A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs. An attacker… | |
| Modificada | Alta (8.6) | 0.87% | — | Cisco Catalyst 9166 FirmwareCisco Catalyst 9164 FirmwareCisco Catalyst 9136 FirmwareCisco Catalyst 9130 Firmware+1 | 27/9/2023 | 17/6/2026 | A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as… | |
| Modificada | Media (4.8) | 0.37% | — | Catalystconnect Catalyst Connect Zoho CRM Client Portal | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions. | |
| Modificada | Media (6.5) | 1.7% | — | Cisco Catalyst Sd-wan Manager | 4/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could… | |
| Modificada | Alta (8.1) | 0.74% | — | Cisco Catalyst Sd-wan Manager | 4/8/2023 | 17/6/2026 | A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker… | |
| Modificada | Crítica (9.1) | 0.92% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 3/8/2023 | 17/6/2026 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient… | |
| Modificada | Media (6.1) | 0.46% | — | Catalystconnect Zoho CRM Client Portal | 27/6/2023 | 17/6/2026 | The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin. | |
| Modificada | Media (4.3) | 0.48% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the… | |
| Modificada | Media (4.3) | 0.49% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the… | |
| Modificada | Alta (8.8) | 0.62% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the… | |
| Modificada | Media (6) | 0.51% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 9/5/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this… | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Business 150ax FirmwareCisco Business 151axm FirmwareCisco Catalyst 9105ax FirmwareCisco Catalyst 9105axi Firmware+27 | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.5) | 0.41% | — | Cisco Catalyst Center | 23/3/2023 | 17/6/2026 | A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text. The attacker must have valid low-privileged user credentials. This vulnerability is due to improper role-based access… | |
| Modificada | Alta (8.8) | 0.74% | — | Cisco Catalyst Center | 23/3/2023 | 17/6/2026 | A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device. This vulnerability is due to the unintended exposure of sensitive information. An attacker could exploit this… | |
| Modificada | Media (6.1) | 0.53% | — | Catalyst-plugin-session Project Catalyst-plugin-session | 28/12/2022 | 17/6/2026 | A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component Session ID Handler. The manipulation of the argument sid leads to cross site scripting. The attack can… | |
| Modificada | Media (5.3) | 0.74% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 10/10/2022 | 17/6/2026 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exists because the GUI is accessible on self-managed cloud… | |
| Modificada | Media (6.5) | 0.46% | — | Cisco Catalyst 9800-l FirmwareCisco Catalyst 9800-40 FirmwareCisco Catalyst 9800-80 FirmwareCisco Catalyst 9800-cl Firmware | 30/9/2022 | 17/6/2026 | A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain parameters within… | |
| Modificada | Media (6.7) | 0.26% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Sd-wan Vsmart Controller+1 | 30/9/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands that are executed as… | |
| Analizada | Alta (7.8) | 12% | ⚠ Explotación activa | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vedge CloudCisco Sd-wan Vsmart Controller+1 | 30/9/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the… | |
| Modificada | Media (4.7) | 0.27% | — | Cisco Aironet 1542d FirmwareCisco Aironet 1542i FirmwareCisco Aironet 1562i FirmwareCisco Aironet 1562e Firmware+22 | 30/9/2022 | 17/6/2026 | A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are… |