Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Cisco IOS XR | 31/5/2011 | 16/6/2026 | Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4 packet, aka Bug ID CSCth44147. | |
| Analizada | Alta (7.5) | 5.7% | ⚠ Explotación activa | Cisco IOS XR | 30/8/2010 | 16/6/2026 | Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211. | |
| Modificada | Alta (7.8) | 3.0% | — | Cisco IOSCisco IOS XECisco IOS XR | 25/3/2010 | 16/6/2026 | Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a… | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco IOS XR | 21/1/2010 | 16/6/2026 | Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574. | |
| Modificada | Baja (3.3) | 1.3% | — | Cisco IOS XR | 21/8/2009 | 16/6/2026 | Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path. | |
| Modificada | Baja (3.3) | 1.3% | — | Cisco IOS XR | 21/8/2009 | 16/6/2026 | Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute. | |
| Analizada | Media (5.9) | 3.3% | ⚠ Explotación activa | Cisco IOS XR | 19/8/2009 | 16/6/2026 | Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. | |
| Modificada | Alta (7.1) | 3.3% | — | Cisco IOSCisco IOS XR | 27/3/2009 | 16/6/2026 | The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command. | |
| Modificada | Media (5.4) | 4.0% | — | Cisco IOSCisco IOS XR | 27/3/2009 | 16/6/2026 | The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record… | |
| Modificada | Alta (7.1) | 2.5% | — | Cisco IOS SCisco IOS TCisco IOS XR | 22/5/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293. | |
| Rechazada | Sin puntuar | — | — | Cisco IOSAICisco IOS XRAI | 12/10/2007 | 7/11/2023 | Rejected reason: Multiple stack-based buffer overflows in Cisco IOS 12.x and IOS XR allow attackers to execute arbitrary code, as demonstrated via the "Bind Shell", "Reverse Shell", and "Two byte rootshell (Tiny Shell)" attacks. NOTE: the vendor and researcher agree that this issue does not cross privilege boundaries,… | |
| Modificada | Media (5) | 13% | 💥 Exploit | Cisco CLICisco CbosCisco IDSCisco IOS+1 | 20/8/2007 | 16/6/2026 | Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous… | |
| Modificada | Media (5) | 1.9% | — | Cisco IOS XR | 20/4/2006 | 16/6/2026 | Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2)… | |
| Modificada | Media (5) | 1.8% | — | Cisco IOS XR | 20/4/2006 | 16/6/2026 | Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475. | |
| Modificada | Baja (2.1) | 1.4% | — | Cisco IOSCisco IOS XR | 3/8/2005 | 16/6/2026 | Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet. |