Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.43% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.4) | 0.30% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.3) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.31% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based… | |
| Analizada | Media (6.1) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Aplazada | Media (6) | 0.17% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAICisco FxosAI | 23/10/2024 | 17/6/2026 | A vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to elevate their administrative privileges to root. The attacker would need valid… | |
| Analizada | Media (6.6) | 0.32% | — | Cisco Firepower Extensible Operating SystemCisco Nx-osCisco Unified Computing System | 29/2/2024 | 17/6/2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame.… | |
| Modificada | Media (6) | 0.18% | — | Cisco Firepower Extensible Operating System | 23/8/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker… | |
| Modificada | Media (6.3) | 0.68% | — | Cisco Firepower 9300 FirmwareCisco Firepower 4143 FirmwareCisco Firepower 4112 FirmwareCisco UCS 6324 Fabric Interconnect Firmware+4 | 23/8/2023 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+8 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands… | |
| Modificada | Media (6.7) | 0.29% | — | Cisco Secure Firewall Threat DefenseCisco Firepower Extensible Operating System | 15/11/2022 | 11/8/2026 | A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could… | |
| Modificada | Media (6.5) | 0.53% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco Firepower Services Software FOR ASA | 15/11/2022 | 11/8/2026 | A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a… | |
| Modificada | Alta (7.5) | 0.90% | — | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated,… | |
| Modificada | Media (6.7) | 0.34% | — | Cisco Firepower 4110 FirmwareCisco Firepower 4112 FirmwareCisco Firepower 4115 FirmwareCisco Firepower 4120 Firmware+8 | 25/8/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The attacker would need to have Administrator privileges on the device. This vulnerability is due to insufficient input validation of commands supplied by… | |
| Modificada | Alta (7.2) | 49% | — | Cisco ASA Firepower | 24/6/2022 | 17/6/2026 | A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper… | |
| Modificada | Media (4.3) | 3.3% | — | Cisco Firepower Extensible Operating SystemCisco Nx-os | 23/2/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to a lack of proper error handling when an… | |
| Modificada | Media (6.1) | 0.61% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (4.8) | 0.48% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.1) | 2.0% | — | Cisco Firepower Management Center Virtual ApplianceCisco Secure Firewall Threat DefenseCisco Sourcefire Defense Center | 27/10/2021 | 11/8/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to insufficient input… |