Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
7116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Alta (8.6) | 0.47% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Modificada | Crítica (9) | 0.38% | — | Cisco IOS XE | 5/8/2026 | 2/10/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | |
| Analizada | Alta (8.6) | 0.57% | — | Cisco IOS XE | 5/8/2026 | 28/9/2026 | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker… | |
| Analizada | Media (5.3) | 35% | ⚠ Explotación activa | Cisco Secure Firewall Management Center | 29/7/2026 | 16/9/2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.19% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.46% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (8.8) | 0.42% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Cisco Catalyst 1719 AentrAI | 14/7/2026 | 14/7/2026 | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. | |
| Pendiente de análisis | Media (6) | 0.33% | — | Cisco HyperflexAI | 14/7/2026 | 15/7/2026 | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service. | |
| Analizada | Alta (7.2) | 1.9% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker… | |
| Analizada | Alta (7.2) | 1.5% | — | Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware | 8/7/2026 | 10/7/2026 | An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | 💥 PoC | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning,… | |
| Analizada | Alta (7.5) | 0.57% | — | Cisco Secure EndpointClamav | 1/7/2026 | 9/7/2026 | A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning,… |