Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

7116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.86%—Cisco Staros9/5/202317/6/2026
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a…
ModificadaCrítica (9.8)37%💥 PoCCisco Spa112 Firmware4/5/202317/6/2026
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this…
AnalizadaAlta (7.2)54%⚠ Explotación activaCisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+213/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (6.1)0.43%—Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+25/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input…
ModificadaMedia (4.6)0.25%—Cisco DUOCisco DUO Authentication FOR Windows Logon AND RDP5/4/202317/6/2026
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device. This vulnerability…
ModificadaAlta (7.8)0.20%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.20%—Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaAlta (7.2)30%—Cisco Rv320 FirmwareCisco Rv325 Firmware5/4/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities are due to…
ModificadaAlta (7.2)0.90%—Cisco Secure Network Analytics5/4/202317/6/2026
A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device. This vulnerability is due to insufficient validation of user input to the web interface. An attacker could exploit this vulnerability by uploading a crafted…
ModificadaAlta (8.8)1.0%—Cisco Secure Network AnalyticsCisco Stealthwatch Management Console 2200 Firmware5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that is parsed into system memory. An attacker…