Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.45% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for… | |
| Modificada | Media (5.9) | 0.39% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN service on an affected… | |
| Modificada | Alta (7.5) | 0.52% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions.… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Alta (7.5) | 0.55% | — | Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. This vulnerability is due to insufficient resource management when… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Alta (7.2) | 2.0% | — | Zultys Mx-se FirmwareZultys Mx-se II FirmwareZultys Mx-e FirmwareZultys Mx-virtual Firmware+2 | 8/12/2023 | 17/6/2026 | An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function. The Zultys MX Administrator… | |
| Modificada | Alta (8.8) | 0.69% | — | Zultys Mx-se FirmwareZultys Mx-se II FirmwareZultys Mx-e FirmwareZultys Mx-virtual Firmware+2 | 8/12/2023 | 17/6/2026 | A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in… | |
| Modificada | Crítica (9.8) | 0.92% | — | Zultys Mx-se FirmwareZultys Mx-se II FirmwareZultys Mx-e FirmwareZultys Mx-virtual Firmware+2 | 8/12/2023 | 17/6/2026 | An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation,… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Meraki Mx64 FirmwareCisco Meraki Mx64w FirmwareCisco Meraki Mx65 FirmwareCisco Meraki Mx65w Firmware+19 | 26/10/2022 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters… | |
| Modificada | Media (5.3) | 2.0% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS XESnort+12 | 13/1/2021 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is… |