Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.20% | — | Funkwerk System SoftwareAI | 10/7/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp. | |
| Analizada | Media (6.5) | 0.23% | — | IBM Cloud PAK SystemIBM Cloud PAK System Software Suite | 27/3/2025 | 17/6/2026 | IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user. | |
| Modificada | Alta (7.5) | 0.79% | — | Hiwin Robot System Software | 17/10/2022 | 17/6/2026 | HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition. | |
| Modificada | Alta (7.2) | 1.1% | — | Polycom HDX System Software | 12/3/2020 | 17/6/2026 | An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user is the factor value of a shell script on the equipment. By entering a special… | |
| Modificada | Crítica (9.8) | 3.1% | — | Polycom HDX System Software | 10/2/2020 | 16/6/2026 | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password. | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco Firepower System Software | 8/11/2018 | 17/6/2026 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Intrusion Prevention System (IPS) rule that inspects certain types of TCP traffic. The vulnerability is due to incorrect TCP retransmission handling. An attacker could… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Firepower System Software | 5/10/2018 | 17/6/2026 | A vulnerability in the Server Message Block Version 2 (SMBv2) and Version 3 (SMBv3) protocol implementation for the Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the device to run low on system memory, possibly preventing the device from forwarding traffic. It is also… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Firesight System Software | 7/8/2017 | 17/6/2026 | A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting and inspecting traffic on an affected system. The… | |
| Modificada | Media (6.7) | 0.42% | — | Cisco Firesight System Software | 10/7/2017 | 17/6/2026 | A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1. | |
| Modificada | Alta (7.2) | 10% | — | Bluecoat Advanced Secure GatewayBluecoat Content Analysis System Software | 5/4/2017 | 17/6/2026 | Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges. | |
| Modificada | Crítica (9.8) | 4.4% | — | Avaya VSP Operating System Software | 23/1/2017 | 17/6/2026 | Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Firesight System SoftwareCisco Secure Firewall Management Center | 14/12/2016 | 17/6/2026 | A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass malware detection mechanisms on an affected system. Affected Products: Cisco Firepower Management Center and FireSIGHT… | |
| Modificada | Media (6.5) | 2.2% | — | Cisco Firesight System Software | 14/12/2016 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view the Remote Storage Password. More Information: CSCvb19366. Known Affected Releases: 5.4.1.6. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Firesight System Software | 19/11/2016 | 17/6/2026 | A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass FTP malware detection rules and download malware over an FTP connection. Cisco Firepower System Software is affected when… | |
| Modificada | Alta (8.8) | 0.63% | — | Cisco Firesight System Software | 5/10/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636. | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Firesight System Software | 5/10/2016 | 17/6/2026 | Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467. | |
| Modificada | Alta (7.5) | 0.75% | — | Cisco Firesight System Software | 24/9/2016 | 17/6/2026 | Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585. | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Firesight System Software | 12/9/2016 | 17/6/2026 | Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482. | |
| Modificada | Media (5.4) | 1.1% | — | Cisco Firesight System Software | 12/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz58658. | |
| Modificada | Crítica (9.1) | 1.4% | — | Cisco Firesight System Software | 12/9/2016 | 17/6/2026 | Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503. | |
| Modificada | Alta (7.5) | 2.1% | — | Cisco Firesight System Software | 28/7/2016 | 17/6/2026 | Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737. | |
| Modificada | Alta (8.6) | 1.0% | — | Cisco Firesight System Software | 3/7/2016 | 17/6/2026 | Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Firesight System Software | 5/5/2016 | 17/6/2026 | Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Protection (AMP) for Networks component on these appliances, allows remote attackers to cause a denial of service (packet-processing outage) via crafted packets, aka Bug ID… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco ASA With Firepower ServicesCisco Firesight System Software | 1/4/2016 | 17/6/2026 | Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726. | |
| Modificada | Baja (3.7) | 0.83% | — | Cisco Firesight System Software | 3/3/2016 | 17/6/2026 | Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615. |