Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.1% | — | Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+1 | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+1 | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.6) | 1.9% | — | Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+1 | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.6) | 1.9% | — | Cisco IOS XE Sd-wanCisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan Manager+1 | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Catalyst Center | 20/1/2021 | 17/6/2026 | A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be… | |
| Modificada | Alta (8.8) | 3.7% | — | Cisco Catalyst Center | 20/1/2021 | 17/6/2026 | A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit this vulnerability by providing crafted input during… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Sd-wan FirmwareCisco Sd-wan Vsmart Controller FirmwareCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond Orchestrator | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (8.8) | 0.84% | — | Cisco Catalyst CenterMcafee Agent | 20/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent. The vulnerability is due to… | |
| Modificada | Media (4.8) | 0.82% | — | Cisco Catalyst Center | 13/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Media (6.5) | 0.80% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 6/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system. The vulnerability is due to insufficient authorization checking on an affected system. An attacker could… | |
| Modificada | Media (4.3) | 0.72% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 6/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Media (6.4) | 0.65% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 6/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Modificada | Media (6.4) | 0.65% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 6/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Modificada | Media (6.1) | 0.84% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 6/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Media (6.1) | 0.92% | — | Cisco Catalyst Center | 26/8/2020 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an… | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Catalyst Center | 17/8/2020 | 17/6/2026 | A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP… | |
| Modificada | Media (6.5) | 0.50% | — | Cisco Aironet 1542i FirmwareCisco Aironet 1542d FirmwareCisco Aironet 1562i FirmwareCisco Aironet 1562e Firmware+13 | 15/4/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Media (4.8) | 3.1% | 💥 Exploit | Cisco Catalyst Center | 5/2/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to… | |
| Modificada | Alta (7.8) | 0.47% | — | Sony Catalyst BrowseSony Catalyst Production Suite | 4/12/2019 | 17/6/2026 | A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing… | |
| Modificada | Media (6.5) | 0.46% | — | Cisco Aironet 1540 FirmwareCisco Aironet 1560 FirmwareCisco Aironet 1850 FirmwareCisco Aironet 2800 Firmware+3 | 16/10/2019 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The… | |
| Modificada | Media (6.7) | 0.61% | — | Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+23 | 13/5/2019 | 17/6/2026 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based… |