Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.14% | — | WP UmbrellaAI | 10/8/2026 | 12/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2. | |
| Analizada | Media (6) | 0.10% | — | Cisco Umbrella Virtual Appliance | 17/6/2026 | 22/6/2026 | A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using… | |
| Aplazada | Crítica (9.8) | 23% | — | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Modificada | Media (6.1) | 0.49% | — | Nrel API Umbrella | 20/2/2023 | 17/6/2026 | A vulnerability was found in NREL api-umbrella-web 0.7.1. It has been classified as problematic. This affects an unknown part of the component Admin Data Table Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 0.8.0 is able to address this… | |
| Modificada | Media (6.1) | 0.53% | — | Nrel API Umbrella WEB | 4/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown code of the component Flash Message Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.8.0 is able to address this issue. The name of… | |
| Modificada | Media (6.5) | 0.82% | — | Cisco Secure Firewall Threat DefenseCisco Umbrella Virtual ApplianceCisco Cyber Vision | 15/11/2022 | 11/8/2026 | Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to… | |
| Analizada | Media (5.4) | 0.47% | — | Cisco Umbrella | 4/11/2022 | 22/6/2026 | A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.1) | 0.18% | — | Cisco Umbrella Secure WEB Gateway | 21/4/2022 | 17/6/2026 | A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authenticated, adjacent attacker to bypass the SSL decryption and content filtering policies on an affected system. This vulnerability is due to how the decryption function uses the TLS Sever Name Indication… | |
| Analizada | Alta (7.5) | 1.2% | — | Cisco Umbrella Virtual Appliance | 21/4/2022 | 22/6/2026 | A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a man-in-the-middle… | |
| Modificada | Crítica (9.8) | 1.1% | — | Cisco Umbrella Secure WEB Gateway | 10/2/2022 | 17/6/2026 | A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypass the file inspection feature. This vulnerability is due to insufficient restrictions in the file inspection feature. An attacker could exploit this vulnerability by downloading a crafted payload… | |
| Modificada | Media (4.3) | 0.87% | — | Cisco Umbrella | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashboard that appears when a user attempts to modify their… | |
| Modificada | Media (4.1) | 0.69% | — | Cisco Umbrella | 8/4/2021 | 17/6/2026 | Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.6) | 0.72% | — | Cisco Umbrella | 8/4/2021 | 17/6/2026 | Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Umbrella | 20/1/2021 | 17/6/2026 | A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a… | |
| Modificada | Media (4.4) | 0.18% | — | Cisco Umbrella Roaming Client | 23/9/2020 | 17/6/2026 | A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Umbrella | 18/6/2020 | 17/6/2026 | A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this… | |
| Modificada | Media (4.3) | 0.90% | — | Cisco Umbrella | 6/5/2020 | 17/6/2026 | A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Umbrella | 3/5/2019 | 17/6/2026 | A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application not invalidating an existing session when a user… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Umbrella | 18/4/2019 | 17/6/2026 | A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella. The vulnerability is due to insufficient validation of input parameters passed to that page. An attacker could… | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Umbrella Enterprise Roaming Client | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system… | |
| Modificada | Alta (7.8) | 1.5% | — | Cisco Umbrella Enterprise Roaming ClientCisco Umbrella Roaming Module | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vulnerability is due to improper implementation of file system… | |
| Modificada | Crítica (9.1) | 1.1% | — | Cisco Umbrella | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this vulnerability… | |
| Analizada | Media (6.4) | 0.34% | — | Cisco Umbrella Virtual Appliance | 1/12/2017 | 22/6/2026 | The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily leveraged for remote support and allowed for… | |
| Modificada | Alta (8.2) | 0.35% | — | Cisco Umbrella Virtual Appliance | 16/11/2017 | 22/6/2026 | A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an affected virtual appliance. An attacker could… |