Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.09% | — | Cisco Application Policy Infrastructure ControllerAI | 25/2/2026 | 17/6/2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid… | |
| Analizada | Media (5.7) | 0.10% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition… | |
| Analizada | Media (4.4) | 0.16% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6.7) | 0.19% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (4.8) | 0.28% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the web UI. An authenticated… | |
| Analizada | Alta (7.2) | 0.74% | — | Cisco Application Policy Infrastructure Controller | 28/8/2024 | 17/6/2026 | A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary… | |
| Analizada | Media (4.3) | 0.32% | — | Cisco Application Policy Infrastructure Controller | 28/8/2024 | 17/6/2026 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due… | |
| Modificada | Media (5.4) | 0.44% | — | Cisco Application Policy Infrastructure Controller | 23/8/2023 | 17/6/2026 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an… | |
| Modificada | Alta (8.8) | 0.36% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller | 23/2/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… | |
| Modificada | Media (5.4) | 0.60% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability is due to improper input validation in the web UI. An authenticated… | |
| Modificada | Crítica (9.1) | 1.1% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (7.2) | 1.8% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section… | |
| Modificada | Alta (8.8) | 2.1% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This… | |
| Modificada | Alta (8.8) | 2.0% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper… | |
| Modificada | Crítica (9.1) | 1.3% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Application Policy Infrastructure Controller | 25/8/2021 | 17/6/2026 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an affected system. This vulnerability is due to improper access… | |
| Modificada | Media (6.5) | 1.0% | — | Cisco Application Services EngineCisco Application Policy Infrastructure Controller | 24/2/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities,… | |
| Modificada | Crítica (9.8) | 2.3% | — | Cisco Application Services EngineCisco Application Policy Infrastructure Controller | 24/2/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities,… | |
| Modificada | Crítica (10) | 15% | — | Cisco ACI Multi-site OrchestratorCisco Application Policy Infrastructure Controller | 24/2/2021 | 17/6/2026 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could… | |
| Modificada | Media (5.5) | 0.29% | — | Cisco Application Policy Infrastructure ControllerCisco Application Services Engine | 3/6/2020 | 17/6/2026 | A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could exploit this vulnerability by logging in… | |
| Modificada | Media (5.3) | 1.0% | — | Cisco Application Policy Infrastructure ControllerCisco Application Services Engine | 3/6/2020 | 17/6/2026 | A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An attacker could exploit this… | |
| Modificada | Media (5.3) | 1.0% | — | Cisco Application Policy Infrastructure Controller | 26/1/2020 | 17/6/2026 | A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management… | |
| Modificada | Media (6.5) | 0.63% | — | Cisco Application Policy Infrastructure Controller | 4/7/2019 | 17/6/2026 | A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The… | |
| Modificada | Alta (7.2) | 2.8% | — | Cisco Application Policy Infrastructure Controller | 4/7/2019 | 17/6/2026 | A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affected device. The vulnerability is due to incomplete validation and error checking for the file path… | |
| Modificada | Media (5.4) | 0.81% | — | Cisco Application Policy Infrastructure Controller | 3/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Application Policy Infrastructure Controller | 3/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms for certain components in the… |