Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Cisco Hyperflex Hx220c M5 FirmwareCisco Hyperflex Hx240c M5 FirmwareCisco Hyperflex Hx220c AF M5 FirmwareCisco Hyperflex Hx240c AF M5 Firmware+1 | 18/9/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a… | |
| Modificada | Media (5.3) | 0.65% | — | Cisco Hyperflex Hx220c M5 FirmwareCisco Hyperflex Hx240c M5 FirmwareCisco Hyperflex Hx220c AF M5 FirmwareCisco Hyperflex Hx240c AF M5 Firmware+1 | 18/9/2019 | 17/6/2026 | A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.4) | 0.38% | — | Cisco Hyperflex Hx220c M5 FirmwareCisco Hyperflex Hx240c M5 FirmwareCisco Hyperflex Hx220c AF M5 FirmwareCisco Hyperflex Hx240c AF M5 Firmware+1 | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could… |