Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
–

7116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)0.68%—Cisco Firepower 9300 FirmwareCisco Firepower 4143 FirmwareCisco Firepower 4112 FirmwareCisco UCS 6324 Fabric Interconnect Firmware+423/8/202317/6/2026
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected…
ModificadaAlta (7.4)0.33%—Cisco Nx-os23/8/202317/6/2026
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which…
ModificadaMedia (6.5)0.24%—Cisco Nx-os23/8/202317/6/2026
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is…
ModificadaMedia (5.4)0.58%—Cisco Nx-os23/8/202317/6/2026
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error…
ModificadaAlta (7.5)3.4%—Cisco Secure EndpointCisco Secure Endpoint Private Cloud18/8/202317/6/2026
Una vulnerabilidad en el módulo AutoIt de ClamAV podría permitir a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a un error lógico en la gestión de memoria de un dispositivo afectado. Un atacante podría explotar esta…
ModificadaMedia (4.3)0.27%—Cisco Intersight Virtual Appliance16/8/202317/6/2026
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker could exploit this vulnerability by…
ModificadaMedia (5.3)0.55%—Cisco Unified Contact Center Express16/8/202317/6/2026
A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this…
ModificadaAlta (7.1)0.41%—Cisco DUO Device Health Application16/8/202317/6/2026
A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. This vulnerability is due to insufficient input validation. An…
ModificadaAlta (7.8)0.41%—Cisco Thousandeyes Enterprise Agent16/8/202317/6/2026
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of user-supplied CLI arguments. An attacker could exploit…
ModificadaMedia (6.1)0.46%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to…
ModificadaMedia (6.5)0.33%—Cisco Video Phone 8875 FirmwareCisco IP Phone 6821 With Multiplatform FirmwareCisco IP Phone 6825 With Multiplatform FirmwareCisco IP Phone 6841 With Multiplatform Firmware+1916/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This…
ModificadaMedia (5.5)0.27%—Cisco Thousandeyes Enterprise AgentCisco Thousandeyes Recorder16/8/202317/6/2026
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this…
ModificadaAlta (8.8)0.79%—Cisco Unified Communications Manager16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due…
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaMedia (5.4)0.44%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaAlta (7.5)1.2%—Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora16/8/202317/6/2026
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may…
ModificadaMedia (6.5)0.74%—Cisco Identity Services Engine16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit…
ModificadaCrítica (9.1)0.95%—Cisco Intersight Private Virtual Appliance16/8/202317/6/2026
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due…
ModificadaCrítica (9.1)0.95%—Cisco Intersight Private Virtual Appliance16/8/202317/6/2026
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due…
ModificadaMedia (6.1)0.49%—Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a…
ModificadaMedia (6.1)0.48%—Cisco Encs 5100 FirmwareCisco Encs 5400 FirmwareCisco UCS C220 M5 Rack Server FirmwareCisco UCS E160s M3 Firmware+216/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could…
ModificadaAlta (7.2)41%💥 PoCCisco Telepresence Video Communication Server16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an…
ModificadaMedia (5.3)0.63%—Cisco Asyncos4/8/202317/6/2026
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An…
ModificadaMedia (6.5)1.7%—Cisco Catalyst Sd-wan Manager4/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could…