Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

7080 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.6%⚠ Explotación activaCisco Catalyst Sd-wan Manager30/9/20262/10/2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request…
Pendiente de análisisCrítica (10)0.58%—Cisco ISEAICisco Ise-picAI16/9/202617/9/2026
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by…
Pendiente de análisisCrítica (9.1)0.56%—Cisco ISEAI16/9/202617/9/2026
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure…
Pendiente de análisisCrítica (9.1)0.78%—Cisco ISEAI16/9/202617/9/2026
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insufficient validation…
AnalizadaCrítica (10)14%⚠ Explotación activaCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202625/9/2026
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (5.3)0.38%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP…
AnalizadaMedia (4.9)0.30%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability…
AnalizadaMedia (5.3)0.29%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could…
AnalizadaMedia (5.3)0.32%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal…
Pendiente de análisisMedia (6.5)0.56%—Cisco Broadworks Commpilot Application SoftwareAI16/9/202618/9/2026
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this…
AnalizadaMedia (4.9)0.38%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This…
AnalizadaMedia (5.3)1.3%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the…
AnalizadaMedia (4.9)1.2%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal…
AnalizadaMedia (4.9)1.2%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.…
AnalizadaMedia (4.9)0.48%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit…
AnalizadaMedia (4.9)0.46%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity…
AnalizadaMedia (4.9)0.48%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could…
AnalizadaAlta (7.6)0.41%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability…
AnalizadaAlta (7.2)0.92%—Cisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful…
Pendiente de análisisAlta (8.2)0.46%—Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could…
Pendiente de análisisAlta (8.5)0.44%—Cisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could…