Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.81% | — | Ieee 802.2Ietf P802.1qCisco Catalyst 6503-e FirmwareCisco Catalyst 6504-e Firmware+92 | 27/9/2022 | 17/6/2026 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | |
| Modificada | Alta (8.8) | 0.35% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 8/9/2022 | 17/6/2026 | A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnerability exists because the messaging server container ports… | |
| Modificada | Media (4.4) | 0.24% | — | Cisco Catalyst Sd-wan Manager | 4/5/2022 | 17/6/2026 | A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this… | |
| Modificada | Alta (7.3) | 0.60% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privileged user to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 0.49% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 15/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Media (6.8) | 0.24% | — | Cisco Catalyst Digital Building Series Switches FirmwareCisco IOS Rommon | 15/4/2022 | 17/6/2026 | Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resulting in a permanent denial of service (DoS) condition. For more information… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan SolutionCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vedge Cloud+3 | 15/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device.… | |
| Modificada | Media (4.4) | 0.23% | — | Cisco Catalyst Center | 10/2/2022 | 17/6/2026 | A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability… | |
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Cisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+1 | 4/11/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+1 | 4/11/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform… | |
| Modificada | Crítica (9.8) | 1.7% | — | Cisco Catalyst PON Switch Cgp-ont-1p FirmwareCisco Catalyst PON Switch Cgp-ont-4p FirmwareCisco Catalyst PON Switch Cgp-ont-4pvc FirmwareCisco Catalyst PON Switch Cgp-ont-4tvcw Firmware+1 | 4/11/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform… | |
| Modificada | Media (5.4) | 0.60% | — | Catalyst Mahara | 22/10/2021 | 17/6/2026 | Catalyst IT Ltd Mahara CMS v19.10.2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component groupfiles.php via the Number (Nombre) and Description (Descripción) parameters. | |
| Modificada | Media (4.3) | 0.78% | — | Cisco Catalyst Center | 6/10/2021 | 17/6/2026 | A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit… | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 23/9/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XECisco Embedded Wireless ControllerCisco Catalyst 9800 Firmware | 23/9/2021 | 17/6/2026 | Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These… | |
| Modificada | Media (5.5) | 0.23% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan VmanageCisco Vsmart Controller Firmware+8 | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco Aironet 1542d FirmwareCisco Aironet 1562d FirmwareCisco Aironet 1815m FirmwareCisco Aironet 1830e Firmware+37 | 23/9/2021 | 17/6/2026 | A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A… | |
| Modificada | Media (5.5) | 0.25% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 22/7/2021 | 17/6/2026 | A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive information on an affected system is not sufficiently controlled. An… | |
| Modificada | Alta (7.4) | 0.77% | — | Cisco Catalyst Center | 29/6/2021 | 17/6/2026 | A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Vsmart ControllerCisco Vedge 100 Firmware+7 | 4/6/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges on an affected system. This vulnerability exists because the affected software does not properly restrict access to privileged processes. An attacker could exploit this vulnerability by invoking… | |
| Modificada | Media (6.5) | 2.9% | — | Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+190 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. | |
| Modificada | Media (5.3) | 6.5% | — | NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+162 | 11/5/2021 | 17/6/2026 | An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to… | |
| Modificada | Baja (3.5) | 3.6% | — | Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+177 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary… | |
| Modificada | Baja (2.6) | 2.6% | — | Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+164 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or… |