Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.33%—Cisco Nx-osCisco Unified Computing SystemCisco Unified Computing System Infrastructure AND Unified Computing System Software27/10/201116/6/2026
Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.
ModificadaAlta (7.9)2.1%—Cisco Adaptive Security Appliance SoftwareCisco 5500 Series Adaptive Security ApplianceCisco ASA 5500Cisco Telepresence Multipoint Switch Software+925/2/201116/6/2026
Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x,…
ModificadaAlta (8.3)1.4%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
ModificadaAlta (7.8)2.5%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.
ModificadaAlta (10)2.6%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain sensitive information via a GET request, aka Bug ID CSCte43876.
ModificadaAlta (9)2.8%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671.
ModificadaAlta (9)2.8%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.
ModificadaAlta (9)2.8%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31685.
ModificadaAlta (10)3.3%—Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+325/2/201116/6/2026
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640.
ModificadaAlta (9)1.3%—Cisco Wireless Control System Software17/8/201016/6/2026
SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019.
ModificadaMedia (4.3)0.84%—Cisco Wireless Control System Software10/8/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtg33854.
ModificadaMedia (4.3)1.1%—Cisco Wireless Control System Software10/8/201016/6/2026
Cross-site scripting (XSS) vulnerability in webacs/QuickSearchAction.do in the search feature in the web interface in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x before 7.0.164 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, aka Bug ID CSCtf14288.
ModificadaMedia (5)1.2%—Xerox Workcentre 6400 NET ControllerXerox Workcentre 6400 System Software4/2/201016/6/2026
Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure…
ModificadaAlta (7.8)1.7%—Funkwerk System Software17/1/200816/6/2026
Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.
ModificadaAlta (10)4.1%—Cisco Network Admission Control Manager AND Server System Software4/1/200716/6/2026
Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.
ModificadaAlta (7.8)2.6%—Cisco Network Admission Control Manager AND Server System Software4/1/200716/6/2026
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.
ModificadaMedia (5)2.0%—Cisco Network Admission ControlCisco Network Admission Control Manager AND Server System Software29/8/200616/6/2026
The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the…
ModificadaMedia (5.7)0.64%—Cisco Network Admission Control Manager AND Server System Software31/12/200516/6/2026
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332.
ModificadaAlta (9.4)3.8%—Cisco Network Admission Control Manager AND Server System Software17/12/200516/6/2026
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp.
ModificadaAlta (7.5)1.6%—Cisco Network Admission Control Manager AND Server System Software23/8/200516/6/2026
Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users.