Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.7)0.66%—Cisco FxosAICisco UCS ManagerAI25/2/202617/6/2026
This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the…
AplazadaMedia (4.8)0.18%—Cisco Fxos SoftwareAICisco UCS Manager SoftwareAI25/2/202617/6/2026
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
AplazadaMedia (4.4)0.10%—Cisco UCS ManagerAI25/2/202617/6/2026
—
AplazadaMedia (6.5)0.45%—Cisco UCS ManagerAI25/2/202617/6/2026
—
AplazadaMedia (5.4)0.22%—Cisco Integrated Management ControllerAICisco UCS ManagerAI27/8/202517/6/2026
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to…
AplazadaAlta (7.1)0.43%—Cisco Integrated Management ControllerAICisco UCS ManagerAI27/8/202517/6/2026
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit…
AplazadaMedia (6)0.18%—Cisco UCS ManagerAI27/8/202517/6/2026
A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to read or create a file or overwrite any file on the file system of the underlying operating system of an affected device, including system files.   This vulnerability is due to…
AplazadaMedia (6.5)1.2%—Cisco UCS ManagerAI27/8/202517/6/2026
Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root.   These vulnerabilities are due to…
AnalizadaMedia (5.4)0.23%—Cisco UCS Manager27/8/202518/9/2026
A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based…
ModificadaMedia (6.1)0.83%—Cisco Integrated Management ControllerCisco UCS ManagerCisco Encs 5100 FirmwareCisco Encs 5400 Firmware+216/5/202117/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could…
ModificadaMedia (5.3)29%—Cisco Nx-osCisco UCS ManagerDigi SarosHP X3220nr Firmware+22/6/202017/6/2026
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
ModificadaAlta (7.8)0.44%—Cisco UCS Manager26/2/202017/6/2026
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker…
ModificadaAlta (8.8)1.9%—Cisco Firepower Extensible Operating SystemCisco UCS ManagerCisco Nx-os26/2/202017/6/2026
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated…
ModificadaAlta (7.8)0.48%—Cisco UCS ManagerCisco Fxos26/2/202017/6/2026
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation. An attacker…
ModificadaAlta (7.8)0.89%—Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco Firepower Extensible Operating SystemCisco UCS Manager26/2/202011/8/2026
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including…
ModificadaMedia (6.5)1.6%—Cisco Firepower Extensible Operating SystemCisco FxosCisco IOS XRCisco Nx-os+15/2/202017/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing…
ModificadaAlta (8.8)4.8%—Cisco Nx-osCisco UCS Manager5/2/202017/6/2026
A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain…