Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2765▼ 50 respecto a la semana anterior
Críticas / altas1432▲ 200 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)95▼ 405 respecto a la semana anterior
–

232 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.1%⚠ Explotación activaCisco Catalyst Sd-wan Manager30/9/20261/10/2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request…
AplazadaAlta (8.8)0.36%—Catalyst SealAI24/9/202625/9/2026
Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_action with a version that memoises how a path resolved: which dispatch type matched,…
Pendiente de análisisAlta (8.5)2.3%—Amazon Codecatalyst-blueprintsAI3/9/20268/9/2026
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis…
AplazadaMedia (5.7)0.32%—Catalyst Plugin Static SimpleAI20/8/202628/8/2026
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to…
Pendiente de análisisAlta (7.7)0.42%—Cisco Catalyst Sd-wanAI5/8/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
Pendiente de análisisAlta (8.8)0.31%—Cisco Catalyst Sd-wanAI5/8/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
Pendiente de análisisCrítica (9.1)0.59%—Cisco Catalyst Sd-wanAI5/8/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
Pendiente de análisisCrítica (9.9)0.42%—Cisco Catalyst Sd-wanAI5/8/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities…
Pendiente de análisisCrítica (9.9)0.49%—Cisco Catalyst Sd-wanAI5/8/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
Pendiente de análisisMedia (6.5)0.13%—Cisco Catalyst Sd-wan ManagerAI5/8/20266/8/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included…
AplazadaCrítica (9.8)2.6%—Catalyst View WkhtmltopdfAIWkhtmltopdfAI25/7/202613/8/2026
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation…
Pendiente de análisisAlta (8.7)0.43%—Cisco Catalyst 1719 AentrAI14/7/202614/7/2026
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
AplazadaMedia (4.9)0.32%—Catalystconnect Catalyst Connect Zoho CRM Client PortalAI11/7/202629/9/2026
The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AnalizadaAlta (7.5)0.65%—Cisco Catalyst CenterCisco Catalyst Center Global Manager1/7/202617/9/2026
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
AnalizadaMedia (6.5)28%⚠ Explotación activaCisco Catalyst Sd-wan Manager15/6/202624/7/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input…
AplazadaCrítica (9.1)0.37%—Catalyst Plugin AuthenticationAI9/6/202621/7/2026
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.
AnalizadaAlta (7.8)25%⚠ Explotación activaCisco Catalyst Sd-wan ManagerCisco Sd-wan Vsmart Controller4/6/202623/7/2026
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to…
AplazadaMedia (5.1)0.18%—Perl Catalyst Plugin AuthenticationAI21/5/202623/7/2026
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.
AnalizadaAlta (8.6)1.0%—Cisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML…
AnalizadaMedia (5.4)0.19%—Cisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive…
AnalizadaMedia (5.4)0.19%—Cisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information…
AnalizadaCrítica (10)92%⚠ Explotación activaCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller14/5/202617/6/2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain…
AplazadaAlta (7.5)0.36%—Catalyst Plugin StatsdAI10/5/202624/7/2026
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication…
AnalizadaMedia (5.4)0.16%—Cisco Catalyst Sd-wan Manager25/3/202629/6/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker…
AnalizadaAlta (7.5)32%⚠ Explotación activaCisco Catalyst Sd-wan Manager25/2/202617/6/2026
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the…