Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
8415 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (10) | 0.48% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Crítica (10) | 0.61% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Cisco Unified Intelligence CenterAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Cisco BroadworksAI | 19/8/2026 | 20/8/2026 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.6) | 0.44% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (10) | 0.56% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (10) | 0.49% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Media (5) | 0.44% | — | Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI | 19/8/2026 | 20/8/2026 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | Cisco RoomosAI | 19/8/2026 | 20/8/2026 | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB… | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input… | |
| Pendiente de análisis | Crítica (9.9) | 0.53% | — | Cisco Secure WorkloadAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding… | |
| Pendiente de análisis | Crítica (10) | 0.55% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Aplazada | Media (4.3) | 0.38% | — | DiscourseAI | 17/8/2026 | 18/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing category moderator was not a participant in… | |
| Aplazada | Media (4.3) | 0.27% | — | DiscourseAI | 17/8/2026 | 18/9/2026 | Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group mentions endpoints. This could disclose… | |
| Aplazada | Crítica (9.3) | 0.59% | — | DiscourseAI | 17/8/2026 | 18/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cookie value was rendered into a color… | |
| Aplazada | Media (5.3) | 0.31% | — | DiscourseAI | 17/8/2026 | 18/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor and to search-engine crawlers. This… | |
| Analizada | Alta (8.6) | 1.0% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 11/8/2026 | 16/9/2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,… | |
| Aplazada | Media (4.3) | 0.34% | — | DiscourseAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb did not filter tags… | |
| Aplazada | Alta (7.1) | 0.40% | — | DiscourseAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, could craft parameter values that escaped the intended query and… | |
| Aplazada | Alta (8.7) | 0.43% | — | DiscourseAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. | |
| Aplazada | Baja (2) | 0.48% | — | DiscourseAIDiscourse-local-datesAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and… | |
| Aplazada | Media (6.3) | 0.31% | — | DiscourseAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1. | |
| Aplazada | Media (4.8) | 0.40% | — | DiscourseAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security… |