Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

8451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.73%—Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center3/3/202317/6/2026
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
ModificadaMedia (6.1)0.74%—Cisco Identity Services Engine1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation…
ModificadaMedia (6.7)0.45%💥 PoCCisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…
ModificadaMedia (6.1)0.52%—Cisco Nexus Dashboard1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An…
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaAlta (7.5)0.95%—Cisco Nexus Dashboard1/3/202317/6/2026
A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of…
ModificadaAlta (7.2)1.3%💥 PoCCisco Email Security ApplianceCisco Secure Email AND WEB Manager1/3/202317/6/2026
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user…
ModificadaMedia (5.3)0.68%—Cisco Asyncos1/3/202317/6/2026
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability…
ModificadaMedia (6.5)0.30%—Cisco Nx-os23/2/202317/6/2026
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due…
ModificadaAlta (7.8)0.25%—Cisco Nx-os23/2/202317/6/2026
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit…
ModificadaMedia (6.5)0.11%—Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+823/2/202317/6/2026
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This…
ModificadaMedia (6.7)0.22%—Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+823/2/202317/6/2026
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands…
ModificadaMedia (4.6)0.29%—Cisco Nexus 93180yc-fx3s FirmwareCisco Nexus 93180yc-fx3 FirmwareCisco UCS Central SoftwareCisco UCS 6536 Firmware+223/2/202317/6/2026
A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password…
ModificadaAlta (8.8)0.36%—Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller23/2/202317/6/2026
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This…
ModificadaAlta (7.5)0.55%—Cisco Node-jose16/2/202317/6/2026
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jose` can trigger a Denial-of-Service (DoS) condition, due to a possible infinite…
ModificadaMedia (6.1)0.53%—Discuzx15/2/202317/6/2026
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
ModificadaAlta (8.8)1.5%—Cisco Ic3000 Industrial Compute GatewayCisco IOXCisco IOS XECisco Cgr1240 Firmware+512/2/202317/6/2026
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An…
ModificadaMedia (5.7)0.57%—Discourse8/2/202317/6/2026
Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known…
ModificadaMedia (5.3)0.45%—Discourse3/2/202317/6/2026
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. As a workaround, disable embeddable comments by deleting all…
ModificadaAlta (7.8)1.1%—Mt7688-wiscan Project Mt7688-wiscan1/2/202317/6/2026
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.
ModificadaMedia (5.3)0.59%—Discourse28/1/202317/6/2026
Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y la versión 3.1.0.beta2 en las ramas "beta" y "tests-passed", alguien podía usar el parámetro "exclude_tag" para filtrar temas y deducir cuáles estaban usando una etiqueta oculta específica. Esto afecta a…
ModificadaAlta (7.5)0.87%—Discourse28/1/202317/6/2026
Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y la versión 3.1.0.beta2 en las ramas "beta" y "tests-passed", un usuario malintencionado podía provocar una denegación de servicio de expresión regular utilizando un agente de usuario cuidadosamente manipulado.…
ModificadaMedia (5.3)0.67%—Discourse28/1/202317/6/2026
Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y 3.1.0.beta2 en las ramas "beta" y "tests-passed", usuarios no autorizados podían acceder al contenido de las rutas más recientes/principales para etiquetas restringidas. Este problema se solucionó en la versión…
ModificadaMedia (4.3)0.68%—Discourse28/1/202317/6/2026
Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y 3.1.0.beta2 en las ramas "beta" y "tests-passed", al enviar una solicitud de membresía, no hay límite de caracteres por el motivo proporcionado con la solicitud. Potencialmente, esto podría permitir que un…