Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.54% | — | Cisco Anyconnect VPN ServerAICisco Meraki MXAICisco Meraki Z Series Teleworker GatewayAI | 18/6/2025 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to variable… | |
| Aplazada | Alta (7.7) | 0.69% | — | Cisco AnyconnectAICisco Meraki MXAICisco Meraki Z SeriesAI | 2/4/2025 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user… | |
| Analizada | Media (5.6) | 0.23% | — | Cisco Anyconnect Secure Mobility Client | 12/2/2025 | 17/6/2026 | A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 23/10/2024 | 17/6/2026 | A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.6) | 4.1% | — | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… | |
| Modificada | Alta (7.8) | 5.4% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 28/6/2023 | 17/6/2026 | A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN… | |
| Modificada | Alta (7.8) | 0.24% | — | Cisco Anyconnect Secure Mobility Client | 4/11/2021 | 17/6/2026 | A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker… | |
| Modificada | Alta (7) | 0.18% | — | Cisco Anyconnect Secure Mobility Client | 6/10/2021 | 17/6/2026 | A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This… | |
| Modificada | Media (5.5) | 0.21% | — | Cisco Anyconnect Secure Mobility Client | 16/6/2021 | 17/6/2026 | A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to… | |
| Modificada | Media (6.7) | 0.18% | — | Cisco Anyconnect Secure Mobility Client | 16/6/2021 | 17/6/2026 | A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race… | |
| Modificada | Media (5.5) | 0.21% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 0.53% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Alta (7.8) | 0.23% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Alta (7.8) | 0.25% | — | Cisco Anyconnect Secure Mobility Client | 6/5/2021 | 17/6/2026 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an… | |
| Modificada | Media (5.5) | 0.23% | — | Cisco Anyconnect Secure Mobility Client | 24/2/2021 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Anyconnect Secure Mobility Client | 17/2/2021 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is… | |
| Modificada | Media (5.5) | 0.34% | — | Cisco Anyconnect Secure Mobility ClientMcafee Agent Epolicy Orchestrator Extension | 13/1/2021 | 17/6/2026 | A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker… | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Anyconnect Secure Mobility Client | 13/1/2021 | 17/6/2026 | A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.… | |
| Modificada | Alta (7.3) | 0.45% | — | Cisco Anyconnect Secure Mobility Client | 6/11/2020 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could… | |
| Modificada | Media (5.5) | 0.33% | — | Cisco Anyconnect Secure Mobility Client | 6/11/2020 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could… |