Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.29% | — | Cisco Integrated Management ControllerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could… | |
| Pendiente de análisis | Crítica (9.8) | 0.99% | — | Cisco Integrated Management ControllerAI | 1/4/2026 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could… | |
| Aplazada | Media (5.4) | 0.22% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to… | |
| Aplazada | Alta (7.1) | 0.43% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit… | |
| Aplazada | Alta (8.8) | 0.46% | — | Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+1 | 4/6/2025 | 17/6/2026 | A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient… | |
| Aplazada | Media (5.4) | 0.62% | — | Cisco Integrated Management ControllerAI | 18/11/2024 | 17/6/2026 | A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit… | |
| Aplazada | Alta (8.7) | 33% | — | Cisco Integrated Management ControllerAI | 24/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to… | |
| Aplazada | Alta (8.8) | 1.2% | — | Cisco Integrated Management ControllerAI | 24/4/2024 | 17/6/2026 | A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Integrated Management ControllerCisco UCS ManagerCisco Encs 5100 FirmwareCisco Encs 5400 Firmware+21 | 6/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could… | |
| Modificada | Crítica (9.8) | 4.8% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Integrated Management Controller | 18/11/2020 | 17/6/2026 | Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these… | |
| Modificada | Alta (8.8) | 1.9% | — | Cisco Integrated Management Controller | 6/11/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this… | |
| Modificada | Media (4.3) | 0.68% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 6/5/2020 | 17/6/2026 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect… | |
| Modificada | Crítica (9.8) | 4.5% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is… | |
| Modificada | Crítica (9.8) | 76% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user… | |
| Modificada | Alta (7.2) | 39% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of… | |
| Modificada | Crítica (9.8) | 83% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A… | |
| Modificada | Alta (8.8) | 1.4% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected… | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on… | |
| Modificada | Alta (7.2) | 1.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request… | |
| Modificada | Alta (7.2) | 3.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software.… | |
| Modificada | Alta (7.8) | 0.41% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Alta (7.2) | 3.3% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper… | |
| Modificada | Alta (8.8) | 3.6% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied… |