Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Cisco Small Business Sa520 FirmwareCisco Small Business Sa540 Firmware | 23/10/2017 | 17/6/2026 | Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Sa520Cisco Sa520wCisco Sa540Cisco Rv016 Multi-wan VPN Firmware+3 | 13/12/2015 | 17/6/2026 | The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224. | |
| Modificada | Alta (9) | 2.2% | — | Cisco Sa500 SoftwareCisco Sa520Cisco Sa520wCisco Sa540 | 28/7/2011 | 16/6/2026 | The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execute arbitrary commands via crafted parameters to web forms, aka Bug ID CSCtq65681. | |
| Modificada | Media (5) | 1.1% | — | Cisco Sa500 SoftwareCisco Sa520Cisco Sa520wCisco Sa540 | 28/7/2011 | 16/6/2026 | SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtq65669. |