Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 0.98% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel… | |
| Modificada | Media (6.5) | 0.30% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of received traffic.… | |
| Modificada | Media (6.5) | 1.7% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 0.21% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.5) | 0.41% | — | Cisco Catalyst Center | 23/3/2023 | 17/6/2026 | Una vulnerabilidad en la implementación del agente Cisco Network Plug-and-Play (PnP) de Cisco DNA Center podría permitir que un atacante remoto autenticado acceda a información confidencial en texto plano. El atacante debe tener credenciales de usuario válidas con privilegios bajos. Esta vulnerabilidad se debe a un… | |
| Modificada | Media (5.5) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 0.74% | — | Cisco Catalyst Center | 23/3/2023 | 17/6/2026 | Una vulnerabilidad en la API de administración de Cisco DNA Center podría permitir que un atacante remoto autenticado eleve privilegios en el contexto de la interfaz de administración web de un dispositivo afectado. Esta vulnerabilidad se debe a la exposición involuntaria de información confidencial. Un atacante… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco IOS XE Sd-wan | 23/3/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 0.17% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this… | |
| Modificada | Alta (8.6) | 0.98% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs… | |
| Modificada | Alta (7.8) | 0.19% | — | Cisco Enterprise NFV Infrastructure Software | 10/3/2023 | 17/6/2026 | A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker… | |
| Modificada | Media (4.6) | 0.26% | — | Cisco IOS XR | 9/3/2023 | 17/6/2026 | A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB… | |
| Modificada | Alta (7.5) | 1.0% | — | Cisco IOS XR | 9/3/2023 | 17/6/2026 | A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a… | |
| Modificada | Media (6.1) | 0.48% | — | Cisco Webex Teams | 3/3/2023 | 17/6/2026 | A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.80% | — | Cisco Finesse | 3/3/2023 | 17/6/2026 | A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer. This vulnerability is due to improper… | |
| Modificada | Alta (7.5) | 10% | — | Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+17 | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 10% | — | Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+13 | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due… | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.5) | 0.73% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Identity Services Engine | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation… | |
| Modificada | Media (6.7) | 0.45% | 💥 PoC | Cisco Email Security Appliance | 1/3/2023 | 17/6/2026 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A… | |
| Modificada | Media (6.1) | 0.52% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An… | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… |