Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Cisco Firepower Threat DefenseCisco Secure Firewall Threat Defense | 22/5/2017 | 11/8/2026 | A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software 5.3.0 through 6.2.2 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging… | |
| Modificada | Media (4.4) | 0.80% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb66189 CSCvb86775. Known… | |
| Modificada | Alta (7.1) | 0.82% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61384 CSCvb86764. Known… | |
| Modificada | Alta (7.8) | 0.81% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61351 CSCvb61637. Known… | |
| Modificada | Media (6.7) | 0.40% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 7/4/2017 | 17/6/2026 | A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation. More… | |
| Modificada | Alta (7.8) | 0.81% | — | Cisco Unified Computing SystemCisco Firepower Extensible Operating System | 7/4/2017 | 17/6/2026 | A vulnerability in the local-mgmt CLI command of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection attack. More Information: CSCvb61394… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Firepower Services FOR Adaptive Security Appliance | 14/12/2016 | 17/6/2026 | A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services, Advanced… | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco ASA With Firepower Services | 5/5/2016 | 17/6/2026 | The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0 misconfigures kernel logging, which allows remote attackers to cause a denial of service (resource consumption, and inspection outage or module outage) via a flood… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco ASA With Firepower ServicesCisco Firesight System Software | 1/4/2016 | 17/6/2026 | Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726. | |
| Modificada | Crítica (9.8) | 8.7% | — | Cisco Firepower Extensible Operating SystemCisco Unified Computing System | 22/1/2016 | 17/6/2026 | An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Firepower Extensible Operating System | 24/11/2015 | 17/6/2026 | An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622. | |
| Modificada | Media (4.3) | 0.82% | — | Cisco Firepower Extensible Operating System | 19/11/2015 | 17/6/2026 | The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604. | |
| Modificada | Media (4) | 0.97% | — | Cisco Firepower Extensible Operating System | 19/11/2015 | 17/6/2026 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621. | |
| Modificada | Alta (7.2) | 0.39% | — | Cisco Firepower Extensible Operating System | 19/11/2015 | 17/6/2026 | The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578. | |
| Modificada | Media (4.9) | 0.31% | — | Cisco Firepower Extensible Operating System | 19/11/2015 | 17/6/2026 | The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531. | |
| Modificada | Media (5) | 1.2% | — | Cisco Firepower Extensible Operating System | 19/11/2015 | 17/6/2026 | Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608. | |
| Modificada | Media (6.8) | 0.59% | — | Cisco Firepower Extensible Operating System | 18/11/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611. | |
| Modificada | Media (4.3) | 0.96% | — | Cisco Firepower Extensible Operating System | 18/11/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614. | |
| Modificada | Media (6.1) | 0.70% | — | Cisco Firepower | 28/9/2015 | 17/6/2026 | Cisco FirePOWER (formerly Sourcefire) 7000 and 8000 devices with software 5.4.0.1 allow remote attackers to cause a denial of service (inspection-engine outage) via crafted packets, aka Bug ID CSCuu10871. | |
| Modificada | Media (5) | 1.3% | — | Cisco Firepower Extensible Operating System | 29/7/2015 | 17/6/2026 | Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230. | |
| Modificada | Alta (7.8) | 2.3% | — | Cisco ASA With Firepower ServicesCisco ASA CX Context-aware Security Software | 11/4/2015 | 17/6/2026 | The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and… |