Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.1% | — | Cisco Telepresence System Tx9000Cisco Telepresence System Tx9200Cisco Telepresence System SoftwareCisco Telepresence System 1300+7 | 8/8/2013 | 16/6/2026 | Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug… | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… | |
| Modificada | Media (6.8) | 1.7% | — | Cisco Telepresence System Software | 31/5/2013 | 16/6/2026 | Cisco TelePresence System Software does not properly handle inactive t-shell sessions, which allows remote authenticated users to cause a denial of service (memory consumption and service outage) by establishing multiple SSH connections, aka Bug ID CSCug77610. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Unified Computing System Software | 29/4/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in a Flash component in Cisco Unified Computing System (UCS) Central allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud15430. | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted authentication request to a Cisco Integrated Management Controller (IMC), aka Bug ID CSCts53746. | |
| Modificada | Alta (9.3) | 1.8% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug ID CSCtq86543. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remote attackers to cause a denial of service (service outage) via a malformed request, aka Bug ID CSCtg48206. | |
| Modificada | Alta (10) | 3.6% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+1 | 25/4/2013 | 16/6/2026 | Buffer overflow in the Intelligent Platform Management Interface (IPMI) functionality in the Manager component in Cisco Unified Computing System (UCS) 1.0 and 1.1 before 1.1(1j) and 1.2 before 1.2(1b) allows remote attackers to execute arbitrary code via malformed data in a UDP packet, aka Bug ID CSCtd32371. | |
| Modificada | Alta (9.3) | 3.5% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System SoftwareCisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric Interconnect+2 | 25/4/2013 | 16/6/2026 | The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) allows remote attackers to bypass LDAP authentication via a malformed request, aka Bug ID CSCtc91207. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Nx-osCisco Nexus 5548pCisco Nexus 5548upCisco Nexus 5596up+8 | 25/4/2013 | 16/6/2026 | Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 devices before 2.0(1w) allows remote attackers to cause a denial of service (device reload) by sending a jumbo packet to the management interface, aka Bug IDs CSCtx17544,… | |
| Modificada | Alta (8.3) | 1.4% | — | Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+23 | 25/4/2013 | 16/6/2026 | Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V… | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco Network Admission Control Manager AND Server System Software | 18/4/2013 | 16/6/2026 | SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Prime Network Control System SoftwareCisco Prime Network Control System | 11/4/2013 | 16/6/2026 | The Cisco Prime Network Control System (NCS) appliance with software before 1.1.1.24 has a default password for the database user account, which makes it easier for remote attackers to change the configuration or cause a denial of service (service disruption) via unspecified vectors, aka Bug ID CSCtz30468. | |
| Modificada | Media (4.3) | 1.6% | — | Juniper Networks Mobility System Software | 3/4/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via… | |
| Modificada | Media (4.3) | 1.1% | — | Polycom HDX System Software | 1/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface on Polycom HDX Video End Points with UC APL software before 2.7.1.1_J, and commercial software before 3.0.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System Software | 6/8/2012 | 16/6/2026 | The Fabric Interconnect component in Cisco Unified Computing System (UCS) 2.0 allows remote attackers to cause a denial of service (process crash) via an attempted SSH session, aka Bug ID CSCtt94543. | |
| Modificada | Media (4) | 0.98% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System Software | 6/8/2012 | 16/6/2026 | Cisco Unified Computing System (UCS) 1.4 and 2.0 allows remote authenticated users to cause a denial of service (device reload) via a malformed SNMP request to a Fabric Interconnect (FI) device, aka Bug ID CSCts32463. | |
| Modificada | Media (4) | 0.98% | — | Cisco Unified Computing System Infrastructure AND Unified Computing System Software | 6/8/2012 | 16/6/2026 | Cisco Unified Computing System (UCS) 1.4 and 2.0 allows remote authenticated users to cause a denial of service (device reload) via a malformed SNMP request to a Fabric Interconnect (FI) device, aka Bug ID CSCts32452. | |
| Modificada | Alta (9) | 2.2% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1300 65Cisco Telepresence System 3000Cisco Telepresence System 3010+7 | 12/7/2012 | 16/6/2026 | The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724. | |
| Modificada | Alta (8.3) | 1.2% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1300 65Cisco Telepresence System 3000Cisco Telepresence System 3010+7 | 12/7/2012 | 16/6/2026 | An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382. | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+11 | 12/7/2012 | 16/6/2026 | The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP… | |
| Modificada | Alta (8.3) | 1.7% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+11 | 12/7/2012 | 16/6/2026 | The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by… | |
| Modificada | Media (4) | 0.93% | — | Cisco Wireless Control System Software | 2/5/2012 | 16/6/2026 | The TAC Case Attachment tool in Cisco Wireless Control System (WCS) 7.0 allows remote authenticated users to read arbitrary files under webnms/Temp/ via unspecified vectors, aka Bug ID CSCtq86807. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Telepresence System SoftwareCisco Telepresence Video Communication Server | 1/3/2012 | 16/6/2026 | Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Telepresence System SoftwareCisco Telepresence Video Communication Server | 1/3/2012 | 16/6/2026 | Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426. |