Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Cisco Secure Firewall Management Center | 6/7/2019 | 17/6/2026 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Secure Firewall Management Center | 6/7/2019 | 17/6/2026 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities… | |
| Modificada | Media (5.8) | 1.7% | — | Cisco Secure Firewall Management Center | 16/5/2019 | 17/6/2026 | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due to improper parsing of specific attributes in a TLS packet header. An… | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Secure Firewall Management Center | 16/5/2019 | 17/6/2026 | A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies. The vulnerability is due to improper validation of ICMP packets. An attacker could exploit this vulnerability by sending crafted ICMP… | |
| Modificada | Alta (7.8) | 0.68% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 3/5/2019 | 11/8/2026 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific… | |
| Modificada | Alta (7.8) | 0.66% | — | Cisco Secure Firewall Management Center | 3/5/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting commands into arguments for a specific… | |
| Modificada | Alta (7.4) | 1.8% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 3/5/2019 | 11/8/2026 | Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details… | |
| Modificada | Media (4.8) | 0.85% | — | Cisco Secure Firewall Management Center | 18/4/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Secure Firewall Management Center | 7/2/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation… | |
| Modificada | Media (6.1) | 3.9% | 💥 Exploit | Cisco Secure Firewall Management Center | 23/1/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to… | |
| Modificada | Alta (7.5) | 3.1% | — | Cisco Secure Firewall Management Center | 10/1/2019 | 17/6/2026 | A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because the… | |
| Modificada | Media (6.8) | 1.2% | — | Cisco Secure Firewall Management CenterCisco Adaptive Security Appliance Software | 5/10/2018 | 17/6/2026 | A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Secure Firewall Management Center | 16/7/2018 | 17/6/2026 | A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. The vulnerability is due to improper input… | |
| Modificada | Media (5.8) | 2.5% | — | Cisco Secure Firewall Management Center | 16/7/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because the affected software incorrectly handles TCP packets that… | |
| Modificada | Alta (8.6) | 3.0% | — | Cisco Secure Firewall Management Center | 16/7/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the transfer of files to an affected system via FTP. The vulnerability exists because the affected software incorrectly handles FTP control… | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Secure Firewall Management Center | 16/7/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause one of the detection engine processes to run out of memory and thus slow down traffic processing. The vulnerability is due to improper handling of traffic when the Secure Sockets Layer… | |
| Modificada | Alta (8.8) | 0.94% | — | Cisco Secure Firewall Management CenterCisco Firepower Appliance 8360 FirmwareCisco Firepower Management Center 2500 FirmwareCisco Firepower Appliance 8120 Firmware+28 | 21/6/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the… | |
| Modificada | Media (5.8) | 1.9% | — | Cisco Secure Firewall Management Center | 7/6/2018 | 17/6/2026 | A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect… | |
| Modificada | Media (5.8) | 1.4% | — | Cisco Secure Firewall Management Center | 2/5/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of Transport… | |
| Modificada | Media (5.8) | 1.4% | — | Cisco Secure Firewall Management Center | 2/5/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The vulnerability is due to the incorrect handling of a… | |
| Modificada | Media (6.5) | 2.1% | — | Cisco Secure Firewall Management Center | 2/5/2018 | 17/6/2026 | A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections for the WebSocket protocol. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.6) | 2.4% | — | Cisco Secure Firewall Management Center | 19/4/2018 | 17/6/2026 | A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Secure Firewall Management Center | 16/11/2017 | 17/6/2026 | A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is due to the incorrect detection of an SMB2 file when the detection… | |
| Modificada | Alta (8.6) | 1.6% | — | Cisco Secure Firewall Management Center | 5/10/2017 | 17/6/2026 | A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability. If this memory leak persists over time, a… | |
| Modificada | Alta (8.6) | 1.6% | — | Cisco Secure Firewall Management Center | 5/10/2017 | 17/6/2026 | A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly. The vulnerability is due to improper input… |