Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.54%—Cisco Anyconnect VPN ServerAICisco Meraki MXAICisco Meraki Z Series Teleworker GatewayAI18/6/202517/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to variable…
AplazadaAlta (7.7)0.69%—Cisco AnyconnectAICisco Meraki MXAICisco Meraki Z SeriesAI2/4/202517/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user…
AplazadaMedia (5.3)0.36%—Cisco Meraki Mx67AICisco Meraki Mx68AI4/3/202517/6/2026
A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the…
ModificadaMedia (5.3)0.45%—Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+212/10/202417/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for…
ModificadaMedia (5.9)0.39%—Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+212/10/202417/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN service on an affected…
ModificadaAlta (7.5)0.52%—Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+212/10/202417/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions.…
ModificadaAlta (7.5)0.51%—Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+212/10/202417/6/2026
Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of…
ModificadaAlta (7.5)0.55%—Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+212/10/202417/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. This vulnerability is due to insufficient resource management when…
ModificadaAlta (7.5)0.51%—Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+212/10/202417/6/2026
Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of…
ModificadaAlta (7.5)0.51%—Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+212/10/202417/6/2026
Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of…
ModificadaMedia (5.8)0.52%—Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Unified Threat DefenseCisco Meraki MX Security Appliance Firmware1/11/202311/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this…
ModificadaMedia (5.8)0.95%—Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Meraki MX Security Appliance Firmware15/11/202211/8/2026
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to…
ModificadaAlta (8.6)1.1%—Cisco Meraki Mx64 FirmwareCisco Meraki Mx64w FirmwareCisco Meraki Mx65 FirmwareCisco Meraki Mx65w Firmware+1926/10/202217/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters…
ModificadaMedia (6.5)3.1%—Alfa Awus036h FirmwareCisco Meraki Gr10 FirmwareCisco Meraki Gr60 FirmwareCisco Meraki Mr20 Firmware+9111/5/202117/6/2026
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP…
ModificadaMedia (6.5)2.9%—Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+19011/5/202117/6/2026
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
ModificadaMedia (5.3)6.5%—NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+16211/5/202117/6/2026
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to…
ModificadaBaja (3.5)3.6%—Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+17711/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary…
ModificadaBaja (2.6)2.6%—Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+16411/5/202117/6/2026
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or…
ModificadaMedia (5.3)2.0%—Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS XESnort+1213/1/202111/8/2026
Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is…
ModificadaMedia (6.5)1.6%—Cisco Meraki MR 24 FirmwareCisco Meraki MR 25 FirmwareCisco Meraki MS 10 FirmwareCisco Meraki MS 9 Firmware+38/11/201817/6/2026
A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish…
ModificadaAlta (7.7)0.73%—Cisco Meraki MR FirmwareCisco Meraki MRCisco Meraki MS FirmwareCisco Meraki MS+224/12/201417/6/2026
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565.
ModificadaAlta (7.2)0.34%—Cisco Meraki MX FirmwareCisco Meraki MXCisco Meraki MS FirmwareCisco Meraki MS+224/12/201417/6/2026
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077.
ModificadaMedia (5.4)0.68%—Cisco Meraki MR FirmwareCisco Meraki MRCisco Meraki MX FirmwareCisco Meraki MX+224/12/201417/6/2026
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
ModificadaBaja (3.3)0.57%—Cisco Meraki MX FirmwareCisco Meraki MR FirmwareCisco Meraki MS Firmware24/12/201417/6/2026
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to obtain sensitive credential information by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00302012.