Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

161 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.27%—Cisco Evolved Programmable Network Manager1/4/20262/7/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API…
AnalizadaMedia (6.1)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure4/2/202629/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP…
AnalizadaMedia (4.8)0.26%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AplazadaMedia (6.9)0.37%—Tibbo Aggregate Network ManagerAI23/10/202517/6/2026
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.
AplazadaMedia (6.9)0.53%—Tibbo Aggregate Network ManagerAI23/10/202517/6/2026
Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user…
AnalizadaBaja (2.4)0.20%—Ericsson Network Manager13/10/202517/6/2026
Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.
AnalizadaMedia (6.9)0.30%—Ericsson Network Manager13/10/202517/6/2026
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
AnalizadaAlta (8.8)0.32%—Cisco Evolved Programmable Network Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An…
AnalizadaMedia (4.8)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AnalizadaMedia (6.5)0.32%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
AnalizadaMedia (6.5)0.42%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure20/8/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. This vulnerability is due to…
AnalizadaMedia (4.3)0.32%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager16/7/202529/6/2026
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker…
AnalizadaMedia (4.8)0.29%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure2/4/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. The vulnerability exists…
AnalizadaMedia (6.1)0.31%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager2/4/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is…
AnalizadaMedia (6.3)0.43%—Cisco Prime Data Center Network Manager18/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit access to resources that are intended for users with…
AnalizadaAlta (8.1)0.51%—Cisco Data Center Network Manager18/11/202417/6/2026
A vulnerability in a certain REST API endpoint of Cisco&nbsp;Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this…
AnalizadaMedia (6.1)0.51%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco&nbsp;PI and Cisco&nbsp;EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate…
AnalizadaMedia (6.5)1.7%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco&nbsp;PI and Cisco&nbsp;EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system. This vulnerability is due to…
AnalizadaMedia (5.4)0.28%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure6/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists…
ModificadaAlta (7.1)0.44%—Ericsson Network Manager4/4/202417/6/2026
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the…
ModificadaMedia (6.5)0.55%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure17/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters.…
ModificadaMedia (6.7)0.18%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure17/1/202417/6/2026
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit…
ModificadaAlta (7.2)0.69%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure17/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could…
ModificadaMedia (4.8)0.36%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure17/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this…
ModificadaAlta (8.8)0.78%—Ericsson Network Manager7/12/202317/6/2026
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.