Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.81% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known… | |
| Modificada | Media (6.7) | 0.40% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More… | |
| Modificada | Alta (7.8) | 0.81% | — | Cisco Unified Computing SystemCisco Firepower Extensible Operating System | 7/4/2017 | 17/6/2026 | A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394… | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Unified Computing System Director | 7/4/2017 | 17/6/2026 | A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CSCvc32434. Known Affected Releases: 5.5(0.1) 6.0(0.0). | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Computing System Director | 17/3/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc44344. Known Affected Releases: 6.0(0.0). | |
| Modificada | Alta (8.8) | 0.33% | — | Cisco Unified Computing System Director | 15/2/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulnerability is due to improper role-based access control (RBAC) after the Developer… | |
| Modificada | Alta (7.8) | 0.36% | — | Cisco Unified Computing System | 18/9/2016 | 17/6/2026 | UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263. | |
| Modificada | Alta (8.8) | 2.7% | — | Cisco Unified Computing System Performance Manager | 28/7/2016 | 17/6/2026 | The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unified Computing System Central Software | 21/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250. | |
| Modificada | Alta (8.4) | 0.40% | — | Cisco Unified Computing System Platform Emulator | 16/4/2016 | 17/6/2026 | Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837. | |
| Modificada | Alta (7.8) | 0.37% | — | Cisco Unified Computing System Platform Emulator | 16/4/2016 | 17/6/2026 | Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832. | |
| Modificada | Crítica (9.8) | 2.2% | — | Cisco Unified Computing System Central Software | 14/4/2016 | 17/6/2026 | Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856. | |
| Modificada | Alta (7.5) | 3.9% | — | Cisco Unified Computing SystemCisco Nx-osNetgear Jr6150 FirmwareSamsung X14j Firmware+3 | 3/3/2016 | 17/6/2026 | Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579. | |
| Modificada | Crítica (9.8) | 8.7% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 22/1/2016 | 17/6/2026 | An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888. | |
| Modificada | Alta (7.1) | 2.3% | — | Cisco Unified Computing System | 12/12/2015 | 17/6/2026 | Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757. | |
| Modificada | Media (5) | 2.0% | — | Cisco Unified Computing System Central Software | 5/12/2015 | 17/6/2026 | Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Unified Computing System Central Software | 5/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573. | |
| Modificada | Media (5) | 1.7% | — | Cisco Unified Computing System | 4/11/2015 | 17/6/2026 | The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226. | |
| Modificada | Alta (9.4) | 2.8% | — | Cisco Integrated Management Controller SupervisorCisco Unified Computing System Director | 4/9/2015 | 17/6/2026 | The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625. | |
| Modificada | Media (5) | 1.7% | — | Cisco Unified Computing System Central Software | 29/7/2015 | 17/6/2026 | The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377. | |
| Modificada | Alta (7.2) | 0.44% | — | Cisco Unified Computing System | 20/7/2015 | 17/6/2026 | The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778. | |
| Modificada | Media (4.3) | 0.78% | — | Cisco Unified Computing System | 10/7/2015 | 17/6/2026 | The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133… | |
| Modificada | Alta (7.2) | 0.58% | — | Cisco Unified Computing System | 17/6/2015 | 17/6/2026 | Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795. | |
| Modificada | Alta (10) | 4.5% | — | Cisco Unified Computing System Central Software | 7/5/2015 | 17/6/2026 | Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961. | |
| Modificada | Media (6.8) | 1.0% | — | Cisco Unified Computing System | 26/2/2015 | 17/6/2026 | The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876. |