Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
7115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.27% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input… | |
| Pendiente de análisis | Crítica (9.9) | 0.53% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding… | |
| Pendiente de análisis | Crítica (10) | 0.55% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Analizada | Alta (8.6) | 1.0% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 11/8/2026 | 16/9/2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,… | |
| Analizada | Alta (7.5) | 0.46% | — | Cisco Secure Endpoint | 7/8/2026 | 19/8/2026 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during… | |
| Pendiente de análisis | Alta (7.7) | 0.42% | — | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.31% | — | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Media (6.3) | 0.25% | — | Cisco IOS XEAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An… | |
| Pendiente de análisis | Crítica (9.1) | 0.59% | — | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Media (4.3) | 0.32% | — | Cisco IOS XEAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this… | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.9) | 0.49% | 💥 PoC | Cisco Catalyst Sd-wanAI | 5/8/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOSCisco IOS XE | 5/8/2026 | 17/9/2026 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper… | |
| Pendiente de análisis | Media (6.5) | 0.13% | — | Cisco Catalyst Sd-wan ManagerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included… | |
| Analizada | Media (6.5) | 0.33% | — | Cisco RoomosCisco Roomos Cloud | 5/8/2026 | 17/8/2026 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then… | |
| Analizada | Media (6.5) | 0.64% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 5/8/2026 | 16/9/2026 | — | |
| Analizada | Alta (8.8) | 0.73% | 💥 PoC | Cisco Unified Computing System | 5/8/2026 | 31/8/2026 | — | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | Cisco Integrated Management ControllerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Analizada | Alta (7.7) | 0.50% | — | Cisco IOS XE | 5/8/2026 | 17/9/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests.… | |
| Pendiente de análisis | Media (5) | 0.35% | — | Cisco Terminal Service AgentAI | 5/8/2026 | 6/8/2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least… | |
| Analizada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Crítica (9.8) | 0.57% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… |