Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

7116 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)0.98%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel…
ModificadaMedia (6.5)0.30%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of received traffic.…
ModificadaMedia (6.5)1.7%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this…
ModificadaAlta (7.8)0.21%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by…
ModificadaMedia (6.5)0.41%—Cisco Catalyst Center23/3/202317/6/2026
Una vulnerabilidad en la implementación del agente Cisco Network Plug-and-Play (PnP) de Cisco DNA Center podría permitir que un atacante remoto autenticado acceda a información confidencial en texto plano. El atacante debe tener credenciales de usuario válidas con privilegios bajos. Esta vulnerabilidad se debe a un…
ModificadaMedia (5.5)0.26%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this…
ModificadaAlta (8.8)0.74%—Cisco Catalyst Center23/3/202317/6/2026
Una vulnerabilidad en la API de administración de Cisco DNA Center podría permitir que un atacante remoto autenticado eleve privilegios en el contexto de la interfaz de administración web de un dispositivo afectado. Esta vulnerabilidad se debe a la exposición involuntaria de información confidencial. Un atacante…
ModificadaAlta (7.8)0.22%—Cisco IOS XE Sd-wan23/3/202317/6/2026
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by…
ModificadaAlta (7.8)0.17%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this…
ModificadaAlta (8.6)0.98%—Cisco IOS XE23/3/202317/6/2026
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs…
ModificadaAlta (7.8)0.19%—Cisco Enterprise NFV Infrastructure Software10/3/202317/6/2026
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker…
ModificadaMedia (4.6)0.26%—Cisco IOS XR9/3/202317/6/2026
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB…
ModificadaAlta (7.5)1.0%—Cisco IOS XR9/3/202317/6/2026
A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a…
ModificadaMedia (6.1)0.48%—Cisco Webex Teams3/3/202317/6/2026
A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this…
ModificadaAlta (7.5)0.80%—Cisco Finesse3/3/202317/6/2026
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer. This vulnerability is due to improper…
ModificadaAlta (7.5)10%—Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+173/3/202317/6/2026
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)10%—Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+133/3/202317/6/2026
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due…
ModificadaMedia (4.3)0.53%—Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center3/3/202317/6/2026
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
ModificadaMedia (6.5)0.73%—Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center3/3/202317/6/2026
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
ModificadaMedia (6.1)0.74%—Cisco Identity Services Engine1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation…
ModificadaMedia (6.7)0.45%💥 PoCCisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…
ModificadaMedia (6.1)0.52%—Cisco Nexus Dashboard1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An…
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…