Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
163 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 96% | 💥 Exploit | Cisco Data Center Network Manager | 6/1/2020 | 17/6/2026 | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the… | |
| Modificada | Crítica (9.8) | 3.3% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 26/11/2019 | 17/6/2026 | A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the… | |
| Modificada | Alta (7.8) | 0.32% | — | Cisco Findit Network ManagerCisco Findit Network Probe | 17/7/2019 | 17/6/2026 | A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account with static… | |
| Modificada | Media (5.3) | 79% | 💥 Exploit | Cisco Data Center Network Manager | 27/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could… | |
| Modificada | Alta (7.5) | 30% | — | Cisco Data Center Network Manager | 27/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Cisco Data Center Network Manager | 27/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 83% | 💥 Exploit | Cisco Data Center Network Manager | 27/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on… | |
| Modificada | Media (5.5) | 0.79% | — | SAP Work ManagerSAP Inventory Manager | 12/6/2019 | 17/6/2026 | SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | |
| Modificada | Alta (8.1) | 1.9% | — | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL… | |
| Modificada | Alta (8.1) | 1.9% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL… | |
| Modificada | Alta (7.2) | 4.4% | — | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Alta (7.2) | 4.4% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Crítica (9.8) | 98% | 💥 Exploit | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… | |
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… | |
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… | |
| Modificada | Alta (7.5) | 2.0% | — | SAP Work ManagerSAP Agentry SDK | 8/1/2019 | 17/6/2026 | SAP Work and Inventory Manager (Agentry_SDK , before 7.0, 7.1) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | |
| Modificada | Media (6.5) | 9.1% | 💥 Exploit | Dell Openmanage Network Manager | 30/11/2018 | 17/6/2026 | Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database. | |
| Modificada | Alta (8.8) | 12% | 💥 Exploit | Dell Openmanage Network Manager | 30/11/2018 | 17/6/2026 | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file. | |
| Modificada | Alta (8.1) | 5.4% | — | Cisco Prime Data Center Network Manager | 5/10/2018 | 17/6/2026 | A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of user requests within the management interface. An attacker… | |
| Modificada | Media (6.1) | 0.92% | — | Cisco Data Center Network Manager | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the management interface on an affected device. The vulnerability is due to insufficient validation of… | |
| Modificada | Alta (7.2) | 2.3% | — | Cisco Data Center Network Manager | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands on the underlying operating system with root-level privileges. The vulnerability is due to incomplete input validation of user input within an HTTP request. An attacker… | |
| Modificada | Alta (7.8) | 3.9% | 💥 Exploit | Gnome Network Manager VpncDebian Linux | 26/7/2018 | 17/6/2026 | Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root. | |
| Modificada | Crítica (9.8) | 48% | — | Cisco Prime Data Center Network ManagerCisco Prime Infrastructure | 2/5/2018 | 17/6/2026 | A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network… | |
| Modificada | Alta (8.8) | 1.2% | — | Cisco Data Center Network Manager | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the… |