Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Cisco Secure Firewall Management Center13/1/202117/6/2026
A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability…
ModificadaMedia (4.8)0.61%—Cisco Secure Firewall Management Center13/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerabilities exist because the web-based management…
ModificadaMedia (4.8)0.61%—Cisco Secure Firewall Management Center13/1/202117/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerabilities exist because the web-based management…
ModificadaMedia (5.3)2.2%—Cisco IOS XECisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseSnort13/1/202111/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by…
ModificadaMedia (5.3)2.0%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS XESnort+1213/1/202111/8/2026
Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is…
ModificadaAlta (7.5)2.0%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS XESnort13/1/202111/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could exploit this vulnerability by sending crafted…
ModificadaMedia (5.5)0.26%—Cisco Secure Firewall Management Center13/1/202117/6/2026
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could…
ModificadaMedia (6.1)0.80%—Cisco Secure Firewall Management Center21/10/202017/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit…
ModificadaMedia (5.3)0.73%—Cisco Secure Firewall Management Center21/10/202017/6/2026
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability…
ModificadaMedia (6.1)0.77%—Cisco Secure Firewall Management Center21/10/202017/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied…
ModificadaAlta (8.1)2.2%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense21/10/202011/8/2026
A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to perform directory traversal and access directories outside the restricted path. The vulnerability is due to insufficient input…
ModificadaAlta (8.1)0.96%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense21/10/202011/8/2026
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during…
ModificadaMedia (6.1)0.77%—Cisco Secure Firewall Management Center21/10/202017/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied…
ModificadaMedia (6.7)0.38%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense21/10/202011/8/2026
A vulnerability in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their Cisco FTD instance and execute commands with root privileges in the host namespace. The attacker must have valid credentials on the device.The…
ModificadaAlta (8.6)2.0%—Cisco Secure Firewall Management Center21/10/202017/6/2026
A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.The vulnerability is due to improper handling of system resource values by the affected system. An attacker could exploit this…
ModificadaAlta (8.1)1.1%—Cisco Secure Firewall Management Center21/10/202017/6/2026
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system. The attacker must have a valid CAC to initiate the access attempt. The vulnerability is due to…
ModificadaMedia (5.4)0.63%—Cisco Secure Firewall Management CenterCisco Sourcefire Defense Center8/10/202017/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of…
ModificadaCrítica (9.8)3.4%—Cisco Secure Firewall Management Center23/9/202017/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight…
ModificadaAlta (7.2)4.1%—Cisco Adaptive Security ApplianceCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense23/9/202011/8/2026
A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an…
ModificadaCrítica (9.8)0.96%—Cisco Secure Firewall Management Center6/5/202017/6/2026
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (5.3)2.2%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS6/5/202011/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker…
ModificadaMedia (6.1)0.80%—Cisco Secure Firewall Management Center6/5/202017/6/2026
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the FMC Software. The vulnerability is due to insufficient validation of user-supplied…
ModificadaAlta (7.5)1.1%—Cisco Secure Firewall Management Center6/5/202017/6/2026
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected device. The vulnerability is due to insufficient application identification. An attacker could…
ModificadaMedia (6.1)0.84%—Cisco Secure Firewall Management Center6/5/202017/6/2026
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by…
ModificadaMedia (4.9)0.61%—Cisco Secure Firewall Threat DefenseCisco Secure Firewall Management Center6/5/202011/8/2026
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital…