Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Jenkins Mission ControlAI | 15/11/2025 | 25/6/2026 | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal. | |
| Aplazada | Alta (8.1) | 0.26% | — | Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI | 12/2/2025 | 17/6/2026 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection… | |
| Modificada | Media (5.4) | 0.69% | — | Jenkins Mission Control | 17/12/2019 | 17/6/2026 | Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties. | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco Network Admission Control Manager AND Server System Software | 18/4/2013 | 16/6/2026 | SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095. | |
| Modificada | Media (5.8) | 0.53% | — | Cisco Network Admission Control | 28/2/2013 | 16/6/2026 | The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka Bug ID CSCub24309. | |
| Modificada | Alta (10) | 2.6% | — | Cisco Network Admission Control | 16/4/2008 | 16/6/2026 | Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs. | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco IOS Transmission Control Protocol | 22/5/2007 | 16/6/2026 | Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session. | |
| Modificada | Alta (7.8) | 4.9% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header. | |
| Modificada | Alta (10) | 9.3% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet. | |
| Modificada | Alta (7.8) | 4.5% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device. | |
| Modificada | Alta (10) | 4.1% | — | Cisco Network Admission Control Manager AND Server System Software | 4/1/2007 | 16/6/2026 | Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Network Admission Control Manager AND Server System Software | 4/1/2007 | 16/6/2026 | Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file. | |
| Modificada | Media (5) | 2.0% | — | Cisco Network Admission ControlCisco Network Admission Control Manager AND Server System Software | 29/8/2006 | 16/6/2026 | The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the… | |
| Modificada | Media (5.7) | 0.64% | — | Cisco Network Admission Control Manager AND Server System Software | 31/12/2005 | 16/6/2026 | Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP scripts, a related issue to CVE-2005-4332. | |
| Modificada | Alta (9.4) | 3.8% | — | Cisco Network Admission Control Manager AND Server System Software | 17/12/2005 | 16/6/2026 | Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Network Admission Control Manager AND Server System Software | 23/8/2005 | 16/6/2026 | Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users. |