Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.73% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.1) | 0.74% | — | Cisco Identity Services Engine | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation… | |
| Modificada | Media (6.7) | 0.45% | 💥 PoC | Cisco Email Security Appliance | 1/3/2023 | 17/6/2026 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A… | |
| Modificada | Media (6.1) | 0.52% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An… | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Alta (7.5) | 0.95% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of… | |
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Cisco Email Security ApplianceCisco Secure Email AND WEB Manager | 1/3/2023 | 17/6/2026 | A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user… | |
| Modificada | Media (5.3) | 0.68% | — | Cisco Asyncos | 1/3/2023 | 17/6/2026 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability… | |
| Modificada | Media (6.5) | 0.30% | — | Cisco Nx-os | 23/2/2023 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Nx-os | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit… | |
| Modificada | Media (6.5) | 0.11% | — | Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+8 | 23/2/2023 | 17/6/2026 | A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and configuration backup files. This… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+8 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands… | |
| Modificada | Media (4.6) | 0.29% | — | Cisco Nexus 93180yc-fx3s FirmwareCisco Nexus 93180yc-fx3 FirmwareCisco UCS Central SoftwareCisco UCS 6536 Firmware+2 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability is due to the improper implementation of the password… | |
| Modificada | Alta (8.8) | 0.36% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller | 23/2/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… | |
| Modificada | Alta (7.5) | 0.55% | — | Cisco Node-jose | 16/2/2023 | 17/6/2026 | node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jose` can trigger a Denial-of-Service (DoS) condition, due to a possible infinite… | |
| Modificada | Media (6.1) | 0.53% | — | Discuzx | 15/2/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search. | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Ic3000 Industrial Compute GatewayCisco IOXCisco IOS XECisco Cgr1240 Firmware+5 | 12/2/2023 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An… | |
| Modificada | Media (5.7) | 0.57% | — | Discourse | 8/2/2023 | 17/6/2026 | Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known… | |
| Modificada | Media (5.3) | 0.45% | — | Discourse | 3/2/2023 | 17/6/2026 | Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. As a workaround, disable embeddable comments by deleting all… | |
| Modificada | Alta (7.8) | 1.1% | — | Mt7688-wiscan Project Mt7688-wiscan | 1/2/2023 | 17/6/2026 | Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function. | |
| Modificada | Media (5.3) | 0.59% | — | Discourse | 28/1/2023 | 17/6/2026 | Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y la versión 3.1.0.beta2 en las ramas "beta" y "tests-passed", alguien podía usar el parámetro "exclude_tag" para filtrar temas y deducir cuáles estaban usando una etiqueta oculta específica. Esto afecta a… | |
| Modificada | Alta (7.5) | 0.87% | — | Discourse | 28/1/2023 | 17/6/2026 | Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y la versión 3.1.0.beta2 en las ramas "beta" y "tests-passed", un usuario malintencionado podía provocar una denegación de servicio de expresión regular utilizando un agente de usuario cuidadosamente manipulado.… | |
| Modificada | Media (5.3) | 0.67% | — | Discourse | 28/1/2023 | 17/6/2026 | Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y 3.1.0.beta2 en las ramas "beta" y "tests-passed", usuarios no autorizados podían acceder al contenido de las rutas más recientes/principales para etiquetas restringidas. Este problema se solucionó en la versión… | |
| Modificada | Media (4.3) | 0.68% | — | Discourse | 28/1/2023 | 17/6/2026 | Discourse es una plataforma de discusión de código abierto. Antes de la versión 3.0.1 en la rama "stable" y 3.1.0.beta2 en las ramas "beta" y "tests-passed", al enviar una solicitud de membresía, no hay límite de caracteres por el motivo proporcionado con la solicitud. Potencialmente, esto podría permitir que un… |