Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.33% | — | Cisco Nx-osCisco Unified Computing SystemCisco Unified Computing System Infrastructure AND Unified Computing System Software | 27/10/2011 | 16/6/2026 | Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188. | |
| Modificada | Alta (7.9) | 2.1% | — | Cisco Adaptive Security Appliance SoftwareCisco 5500 Series Adaptive Security ApplianceCisco ASA 5500Cisco Telepresence Multipoint Switch Software+9 | 25/2/2011 | 16/6/2026 | Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x,… | |
| Modificada | Alta (8.3) | 1.4% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587. | |
| Modificada | Alta (7.8) | 2.5% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605. | |
| Modificada | Alta (10) | 2.6% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain sensitive information via a GET request, aka Bug ID CSCte43876. | |
| Modificada | Alta (9) | 2.8% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671. | |
| Modificada | Alta (9) | 2.8% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659. | |
| Modificada | Alta (9) | 2.8% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31685. | |
| Modificada | Alta (10) | 3.3% | — | Cisco Telepresence System SoftwareCisco Telepresence System 1000Cisco Telepresence System 1100Cisco Telepresence System 3000+3 | 25/2/2011 | 16/6/2026 | The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640. | |
| Modificada | Alta (9) | 1.3% | — | Cisco Wireless Control System Software | 17/8/2010 | 16/6/2026 | SQL injection vulnerability in Cisco Wireless Control System (WCS) 6.0.x before 6.0.196.0 allows remote authenticated users to execute arbitrary SQL commands via vectors related to the ORDER BY clause of the Client List screens, aka Bug ID CSCtf37019. | |
| Modificada | Media (4.3) | 0.84% | — | Cisco Wireless Control System Software | 10/8/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtg33854. | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Wireless Control System Software | 10/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webacs/QuickSearchAction.do in the search feature in the web interface in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x before 7.0.164 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, aka Bug ID CSCtf14288. | |
| Modificada | Media (5) | 1.2% | — | Xerox Workcentre 6400 NET ControllerXerox Workcentre 6400 System Software | 4/2/2010 | 16/6/2026 | Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure… | |
| Modificada | Alta (7.8) | 1.7% | — | Funkwerk System Software | 17/1/2008 | 16/6/2026 | Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests. | |
| Modificada | Alta (10) | 4.1% | — | Cisco Network Admission Control Manager AND Server System Software | 4/1/2007 | 16/6/2026 | Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Network Admission Control Manager AND Server System Software | 4/1/2007 | 16/6/2026 | Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file. | |
| Modificada | Media (5) | 2.0% | — | Cisco Network Admission ControlCisco Network Admission Control Manager AND Server System Software | 29/8/2006 | 16/6/2026 | The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the… | |
| Modificada | Media (5.7) | 0.64% | — | Cisco Network Admission Control Manager AND Server System Software | 31/12/2005 | 16/6/2026 | Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332. | |
| Modificada | Alta (9.4) | 3.8% | — | Cisco Network Admission Control Manager AND Server System Software | 17/12/2005 | 16/6/2026 | Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Network Admission Control Manager AND Server System Software | 23/8/2005 | 16/6/2026 | Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users. |