Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 225 respecto a la semana anterior
Críticas / altas1331▼ 100 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 0.74% | — | Cisco Catalyst Center | 23/3/2023 | 17/6/2026 | Una vulnerabilidad en la API de administración de Cisco DNA Center podría permitir que un atacante remoto autenticado eleve privilegios en el contexto de la interfaz de administración web de un dispositivo afectado. Esta vulnerabilidad se debe a la exposición involuntaria de información confidencial. Un atacante… | |
| Modificada | Alta (7.8) | 0.22% | — | Cisco IOS XE Sd-wan | 23/3/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 0.17% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this… | |
| Modificada | Alta (8.6) | 0.98% | — | Cisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs… | |
| Modificada | Alta (8.1) | 0.58% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were being passed to FastImage without SSRF protection. Insufficient protections could enable attackers to trigger outbound network connections from the Discourse server to… | |
| Modificada | Alta (7.5) | 0.56% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass Discourse's server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4-mapped IPv6 address. The issue is patched in the latest beta and… | |
| Modificada | Media (4.9) | 0.65% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the DB. If this is done on a site using… | |
| Modificada | Media (5.4) | 0.53% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on sites with a disabled or overly… | |
| Modificada | Media (6.1) | 0.35% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version 3.1.0.beta3 of the `tests-passed` branch. There… | |
| Modificada | Media (4.3) | 0.53% | — | Discourse | 17/3/2023 | 17/6/2026 | Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of whether the topic is in a read restricted category or not. As a… | |
| Modificada | Media (4.3) | 0.50% | — | Discourse | 16/3/2023 | 17/6/2026 | Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal messages regardless of whether the personal message is visible… | |
| Modificada | Alta (7.8) | 0.19% | — | Cisco Enterprise NFV Infrastructure Software | 10/3/2023 | 17/6/2026 | A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker… | |
| Modificada | Media (4.6) | 0.26% | — | Cisco IOS XR | 9/3/2023 | 17/6/2026 | A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB… | |
| Modificada | Alta (7.5) | 1.0% | — | Cisco IOS XR | 9/3/2023 | 17/6/2026 | A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a… | |
| Modificada | Crítica (9.8) | 1.2% | — | Variscite Matrix-gui | 8/3/2023 | 17/6/2026 | SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint. | |
| Modificada | Media (5.3) | 0.44% | — | Discourse Yearly Review | 6/3/2023 | 17/6/2026 | discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a user present in a yearly review topic that is then anonymised will still have some data linked to its original account. This issue has been patched in commit `b3ab33bbf7` which is included in the… | |
| Modificada | Media (6.1) | 0.48% | — | Ualberta Neosdiscovery | 5/3/2023 | 17/6/2026 | A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely.… | |
| Modificada | Media (5.3) | 0.50% | — | Discourse | 4/3/2023 | 17/6/2026 | Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `tests-passed` version of Discourse. | |
| Modificada | Media (6.1) | 0.48% | — | Cisco Webex Teams | 3/3/2023 | 17/6/2026 | A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.80% | — | Cisco Finesse | 3/3/2023 | 17/6/2026 | A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer. This vulnerability is due to improper… | |
| Modificada | Alta (7.5) | 10% | — | Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+17 | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 10% | — | Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+13 | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due… | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. |