Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.50% | — | Cisco Unified Contact Center Express | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.5) | 0.45% | — | Cisco Webex Meetings | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Webex Meetings | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.57% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Alta (7.2) | 30% | — | Cisco Rv320 FirmwareCisco Rv325 Firmware | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities are due to… | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Prime Infrastructure | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Alta (7.2) | 0.96% | — | Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+2 | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP… | |
| Modificada | Alta (7.5) | 0.87% | — | Cisco Packet Data Network Gateway | 5/4/2023 | 17/6/2026 | A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Cisco Rv340 FirmwareCisco Rv340w FirmwareCisco Rv345 FirmwareCisco Rv345p Firmware | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of… | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Prime Infrastructure | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of… | |
| Modificada | Media (6) | 0.75% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Alta (8.1) | 0.26% | — | Cisco Sd-wan | 23/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Business 150ax FirmwareCisco Business 151axm FirmwareCisco Catalyst 9105ax FirmwareCisco Catalyst 9105axi Firmware+27 | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 0.72% | — | Cisco Adaptive Security ApplianceCisco Secure Firewall Threat Defense | 23/3/2023 | 11/8/2026 | A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote… | |
| Modificada | Media (6.8) | 0.78% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Modificada | Media (6.7) | 0.24% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator… | |
| Modificada | Media (6.8) | 0.38% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to… | |
| Modificada | Media (5.9) | 0.68% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco IOSCisco IOS XE | 23/3/2023 | 11/8/2026 | A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… | |
| Modificada | Alta (7.5) | 0.95% | — | Cisco IOSCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this… |