Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.93% | — | Juniper IVE OSJuniper Secure Access Virtual ApplianceJuniper Fips Secure Access 4000Juniper Fips Secure Access 4500+13 | 1/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter. | |
| Modificada | Media (4) | 0.95% | — | Cisco Secure Access Control System | 15/7/2013 | 16/6/2026 | The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65957. | |
| Modificada | Media (6.8) | 1.2% | — | Cisco Secure Access Control System | 12/7/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCud75177. | |
| Modificada | Media (4.3) | 0.93% | — | Cisco Secure Access Control System | 12/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCud75174. | |
| Modificada | Media (4.3) | 0.93% | — | Cisco Secure Access Control System | 12/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165. | |
| Modificada | Media (4.3) | 0.93% | — | Cisco Secure Access Control System | 12/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Help index page in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75170. | |
| Modificada | Media (4.3) | 0.49% | — | Juniper Junos Pulse Secure Access ServiceJuniper Junos Pulse Access Control Service | 13/6/2013 | 16/6/2026 | Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for… | |
| Modificada | Media (4) | 1.3% | — | Cisco Secure Access Control Server Solution Engine | 12/6/2013 | 16/6/2026 | The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID CSCue79279. | |
| Modificada | Media (6.8) | 1.2% | — | Cisco Secure Access Control System | 16/5/2013 | 16/6/2026 | Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787. | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+7 | 29/4/2013 | 16/6/2026 | The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+6 | 19/2/2013 | 16/6/2026 | The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services… | |
| Modificada | Media (5) | 2.5% | — | Cisco Secure Access Control Server | 7/11/2012 | 16/6/2026 | Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sending a valid username and a crafted password string, aka Bug… | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Secure Access Control Server | 2/5/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192. | |
| Modificada | Media (6.8) | 1.1% | — | Cisco Secure Access Control Server | 2/5/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, aka Bug ID CSCtr78143. | |
| Modificada | Media (5) | 1.5% | — | Avaya Secure Access Link Gateway | 5/8/2011 | 16/6/2026 | The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as… | |
| Modificada | Media (5) | 15% | — | Cisco Secure Access Control System | 4/4/2011 | 16/6/2026 | The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440. | |
| Modificada | Media (4.3) | 1.4% | — | Juniper Secure Access | 15/6/2010 | 16/6/2026 | Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Juniper Secure Access | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to inject arbitrary web script or HTML via the DSSignInURL cookie. | |
| Modificada | Alta (7.5) | 3.0% | — | Cisco Secure ACSCisco Secure Access Control Server | 4/9/2008 | 16/6/2026 | Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote authenticated users to cause a denial… | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Juniper Secure Access 2000 | 6/3/2008 | 16/6/2026 | Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Juniper Secure Access 2000 | 6/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter. | |
| Modificada | Alta (7.5) | 11% | — | Cisco Secure Access Control Server | 9/1/2007 | 16/6/2026 | Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request. | |
| Modificada | Alta (7.8) | 4.3% | — | Cisco Secure Access Control Server | 31/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue… | |
| Modificada | Alta (10) | 13% | — | Cisco Secure Access Control Server | 31/12/2006 | 16/6/2026 | Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet. | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Secure Access Control Server | 26/6/2006 | 16/6/2026 | Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for an administration session, which allows remote attackers to bypass authentication via various methods, aka "ACS Weak Session Management Vulnerability." |