Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover.… | |
| Analizada | Alta (8.6) | 0.98% | 💥 PoC | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper management of resources during fragment reassembly. An… | |
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit… | |
| Analizada | Alta (8.6) | 0.66% | — | Cisco IOS XECisco IOS XE Sd-wan | 25/9/2024 | 17/6/2026 | A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because UTD… | |
| Analizada | Alta (8.8) | 0.30% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based… | |
| Analizada | Alta (7.5) | 0.86% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An… | |
| Analizada | Media (4.3) | 0.26% | — | Cisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (7.5) | 0.63% | — | Cisco IOSCisco IOS XE | 25/9/2024 | 17/6/2026 | A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow when… | |
| Analizada | Media (6.5) | 0.26% | — | Cisco IOS XECisco IOS | 25/9/2024 | 17/6/2026 | A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP… | |
| Modificada | Alta (7.4) | 0.26% | — | Cisco IOS XE | 24/4/2024 | 17/6/2026 | A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco IOSCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An… | |
| Analizada | Alta (7.5) | 0.73% | — | Cisco IOSCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An… | |
| Analizada | Alta (7.4) | 0.29% | — | Cisco Wireless LAN Controller SoftwareCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed… | |
| Analizada | Media (5.5) | 0.15% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This vulnerability is due to improper privilege checks. An attacker could exploit this vulnerability by using the show and show tech wireless CLI… | |
| Analizada | Media (5.3) | 0.45% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL). This vulnerability is due to improper handling of error conditions when a successfully… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Modificada | Alta (7.4) | 0.26% | — | Cisco IOSCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation when… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco IOSCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability… | |
| Analizada | Media (5.5) | 0.10% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX… | |
| Analizada | Media (6.7) | 0.19% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device.… | |
| Analizada | Alta (7.4) | 0.32% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of mDNS client entries. An attacker could exploit… | |
| Analizada | Media (6.5) | 0.55% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF… | |
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Analizada | Alta (8.6) | 0.82% | — | Cisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint… | |
| Modificada | Media (5.3) | 0.56% | — | SnortCisco Secure Firewall Threat DefenseCisco IOS XE | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker… |