Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.46% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to… | |
| Modificada | Media (6.5) | 0.33% | — | Cisco Video Phone 8875 FirmwareCisco IP Phone 6821 With Multiplatform FirmwareCisco IP Phone 6825 With Multiplatform FirmwareCisco IP Phone 6841 With Multiplatform Firmware+19 | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system. This… | |
| Modificada | Media (5.5) | 0.27% | — | Cisco Thousandeyes Enterprise AgentCisco Thousandeyes Recorder | 16/8/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 0.79% | — | Cisco Unified Communications Manager | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Media (5.4) | 0.44% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 16/8/2023 | 17/6/2026 | A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may… | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Identity Services Engine | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Media (6.1) | 0.49% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a… | |
| Modificada | Media (6.1) | 0.48% | — | Cisco Encs 5100 FirmwareCisco Encs 5400 FirmwareCisco UCS C220 M5 Rack Server FirmwareCisco UCS E160s M3 Firmware+2 | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Modificada | Alta (7.2) | 41% | 💥 PoC | Cisco Telepresence Video Communication Server | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an… | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Adiscon Loganalyzer | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) en Adiscon Aiscon LogAnalyze hasta v4.1.13 que permite a un atacante remoto ejecutar código arbitrario a través de los componentes asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, y statistics.php. | |
| Modificada | Media (5.3) | 0.63% | — | Cisco Asyncos | 4/8/2023 | 17/6/2026 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device. The vulnerability is due to improper handling of password-protected zip files. An… | |
| Modificada | Media (6.5) | 1.7% | — | Cisco Catalyst Sd-wan Manager | 4/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could… | |
| Modificada | Alta (8.1) | 0.74% | — | Cisco Catalyst Sd-wan Manager | 4/8/2023 | 17/6/2026 | A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker… | |
| Modificada | Alta (7.5) | 1.0% | — | Projectdiscovery Nuclei | 4/8/2023 | 17/6/2026 | "Nuclei es un escáner de vulnerabilidades. Antes de la versión 2.9.9, un problema de seguridad en el proyecto Nuclei afectaba a los usuarios que utilizaban Nuclei como código Go (SDK) ejecutando plantillas personalizadas. Este problema no afectaba a los usuarios de CLI. El problema estaba relacionado con problemas de… | |
| Modificada | Media (6.1) | 0.45% | — | Cisco Spa500ds FirmwareCisco Spa500s FirmwareCisco Spa501g FirmwareCisco Spa502g Firmware+8 | 3/8/2023 | 17/6/2026 | A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management… | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.3) | 0.62% | — | Cisco Asyncos | 3/8/2023 | 17/6/2026 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper detection of malicious traffic when the… | |
| Modificada | Crítica (9.1) | 0.92% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 3/8/2023 | 17/6/2026 | A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is due to insufficient… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform | 3/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Media (6.1) | 0.53% | — | Cisco Spa500ds FirmwareCisco Spa500s FirmwareCisco Spa501g FirmwareCisco Spa502g Firmware+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An… |