Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

588 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.43%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense1/11/202311/8/2026
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the…
ModificadaCrítica (9.9)16%💥 PoCCisco Secure Firewall Management Center1/11/202317/6/2026
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to…
ModificadaMedia (6.1)0.40%—Cisco Secure Firewall Management Center1/11/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (6.5)0.67%—Cisco Secure Firewall Management Center1/11/202317/6/2026
A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Administrator privileges,…
ModificadaMedia (6.5)0.51%—Cisco Secure Firewall Management Center1/11/202317/6/2026
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability by sending a crafted…
ModificadaMedia (6.1)0.39%—Cisco Secure Firewall Management Center1/11/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (6.1)0.39%—Cisco Secure Firewall Management Center1/11/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (6.1)0.39%—Cisco Secure Firewall Management Center1/11/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaAlta (8.8)0.48%—Microfocus Arcsight Management Center11/8/202317/6/2026
A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Management Center. The vulnerability could be remotely exploited.
ModificadaCrítica (9.8)0.75%—Property Cloud Platform Management Center Project Property Cloud Platform Management Center29/6/202317/6/2026
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
ModificadaAlta (7.5)1.8%—OpensslStormshield Management Center8/2/202317/6/2026
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check…
ModificadaAlta (7.4)60%—OpensslStormshield Management CenterStormshield Network Security8/2/202317/6/2026
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by…
ModificadaAlta (7.5)1.8%—OpensslStormshield Management Center8/2/202317/6/2026
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does…
ModificadaAlta (7.5)4.5%—OpensslStormshield Management Center8/2/202317/6/2026
The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new…
ModificadaAlta (8.8)0.26%—Hospital Management Center Project Hospital Management Center16/11/202217/6/2026
A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.53%—Hospital Management Center Project Hospital Management Center16/11/202217/6/2026
A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.3)0.70%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface together with…
ModificadaMedia (4.3)0.56%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaMedia (4.8)0.50%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
ModificadaAlta (8.8)0.89%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API…
ModificadaAlta (7.2)0.88%—Cisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API…
ModificadaAlta (7.5)0.90%—Cisco Firepower Services Software FOR ASACisco Secure Firewall Management Center15/11/202217/6/2026
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated,…
ModificadaMedia (4.8)0.47%—Cisco Secure Firewall Management Center15/11/202217/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient…
Orbitaley — Vulnerabilidades