Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.48% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Media (4.3) | 0.49% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Alta (8.8) | 0.62% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Media (4.9) | 0.72% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.77% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.40% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (4.9) | 0.49% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 10% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 10% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 10% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Media (6.5) | 1.2% | 💥 PoC | Cisco Smart Software Manager On-prem | 18/5/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An… | |
| Modificada | Baja (3.8) | 0.37% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.84% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these… | |
| Modificada | Media (6.5) | 0.84% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Alta (8.8) | 0.34% | — | Cisco Business 140ac Access Point FirmwareCisco Business 141acm FirmwareCisco Business 142acm FirmwareCisco Business 143acm Firmware+4 | 18/5/2023 | 17/6/2026 | A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit… | |
| Modificada | Media (6) | 0.51% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 9/5/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this… |