Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
588 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 15/11/2022 | 11/8/2026 | A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (4.8) | 0.47% | — | Cisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient… | |
| Modificada | Media (6.5) | 70% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 82% | — | LlhttpNodejs Node.jsDebian LinuxStormshield Management Center | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 46% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that relies on the existence or values of a specific input. An… | |
| Modificada | Alta (8.8) | 4.0% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management… | |
| Modificada | Media (6.1) | 0.75% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Secure Firewall Management Center | 3/5/2022 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied… | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco Snort | 27/10/2021 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive Block with Reset actions if a rule is… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco Unified Threat DefenseSnort | 27/10/2021 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an… |