Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.36% | — | Cisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could… | |
| Modificada | Media (6) | 0.27% | — | Cisco IOS XE Sd-wan | 23/9/2021 | 17/6/2026 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user. This vulnerability is due to insufficient… | |
| Modificada | Media (6.7) | 0.24% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vulnerability is due to insufficient validation of specific CLI command parameters. An attacker could… | |
| Modificada | Alta (7.4) | 0.39% | — | Cisco FxosCisco Firepower Extensible Operating SystemCisco IOSCisco IOS XE+2 | 23/9/2021 | 17/6/2026 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input… | |
| Analizada | Media (5.3) | 1.0% | — | Cisco IOSCisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign… | |
| Modificada | Media (6.5) | 1.2% | — | Cisco IOSCisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper initialization of a buffer. An attacker… | |
| Modificada | Alta (7.7) | 1.2% | — | Cisco IOSCisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect programming of the half-opened… | |
| Modificada | Media (5.8) | 1.00% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than… | |
| Modificada | Media (5.8) | 0.91% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator flows are not inspected when the… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to… | |
| Modificada | Alta (7.7) | 1.1% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR-8 Converged Broadband Routers could allow an authenticated, remote attacker to overload a device punt path, resulting in a denial of service (DoS) condition. This vulnerability is due to the punt path being overwhelmed… | |
| Modificada | Alta (8.6) | 0.98% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code… | |
| Modificada | Alta (7.4) | 0.36% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of certain Layer 2 frames.… | |
| Analizada | Alta (7.7) | 1.1% | — | Cisco IOSCisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release… | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+142 | 23/9/2021 | 17/6/2026 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory… | |
| Modificada | Media (4.7) | 1.2% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data validation of traffic that is traversing the ALG. An attacker… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XE | 23/9/2021 | 17/6/2026 | A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9800 Family Wireless Controller, Embedded Wireless Controller, and Embedded Wireless on Catalyst 9000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of… | |
| Modificada | Alta (8.6) | 1.3% | — | Cisco IOS XECisco Embedded Wireless ControllerCisco Catalyst 9800 Firmware | 23/9/2021 | 17/6/2026 | Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Secure Firewall Threat DefenseCisco IOS XESnort | 29/4/2021 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.1) | 0.27% | — | Cisco IOS XE | 24/3/2021 | 17/6/2026 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions. An attacker could exploit this… | |
| Modificada | Media (6.7) | 0.23% | — | Cisco IOS XE | 24/3/2021 | 17/6/2026 | Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious… | |
| Modificada | Media (6.7) | 0.23% | — | Cisco IOS XE | 24/3/2021 | 17/6/2026 | Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious… | |
| Modificada | Media (4.8) | 0.64% | — | Cisco IOS XE | 24/3/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the web-based management interface of an affected device. The… | |
| Modificada | Alta (8.6) | 1.5% | — | Cisco IOS XE | 24/3/2021 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device.… |