Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.26% | — | Cisco Mobility Express Software | 27/9/2023 | 17/6/2026 | A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause memory leaks that could eventually lead to a device reboot. This vulnerability is due to memory leaks caused by multiple clients connecting under specific conditions.… | |
| Modificada | Media (6.1) | 0.38% | — | Chilexpress-oficial | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chilexpress Chilexpress woo oficial plugin <= 1.2.9 versions. | |
| Modificada | Media (5.3) | 0.55% | — | Cisco Unified Contact Center Express | 16/8/2023 | 17/6/2026 | A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this… | |
| Modificada | Media (4.8) | 0.37% | — | Ihomefinder Optima Express + Marketboost IDX | 14/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ihomefinder Optima Express + MarketBoost IDX Plugin plugin <= 7.3.0 versions. | |
| Modificada | Media (5.4) | 0.55% | — | Expresstech Quiz AND Survey Master | 7/8/2023 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.6) | 0.38% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Crítica (9) | 0.61% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Crítica (9) | 0.61% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Alta (8.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Crítica (9.1) | 2.0% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. | |
| Modificada | Media (5.3) | 27% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter. | |
| Modificada | Media (5.4) | 41% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter. | |
| Modificada | Alta (7.2) | 24% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed. | |
| Modificada | Crítica (9.8) | 37% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/. | |
| Modificada | Alta (7.2) | 1.2% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php. | |
| Modificada | Crítica (9.8) | 26% | — | Audiocodes Device Manager Express | 29/5/2023 | 17/6/2026 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form. | |
| Modificada | Media (5.4) | 0.50% | — | Cisco Unified Contact Center Express | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit… | |
| Modificada | Media (4.8) | 0.39% | — | Thisfunctional CTT Expresso Para Woocommerce | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions. | |
| Modificada | Media (4.8) | 0.35% | — | Tipsandtricks-hq WP Express Checkout | 17/3/2023 | 17/6/2026 | The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject… | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.5) | 0.73% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Alta (8.8) | 0.38% | — | Expresstech Quiz AND Survey Master | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. | |
| Modificada | Alta (8.8) | 1.4% | — | Expressionengine | 9/2/2023 | 17/6/2026 | In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. | |
| Modificada | Media (6.1) | 0.49% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Crítica (9.8) | 0.81% | — | Flitto Express-param | 31/12/2022 | 17/6/2026 | A vulnerability was found in flitto express-param up to 0.x. It has been classified as critical. This affects an unknown part of the file lib/fetchParams.js. The manipulation leads to improper handling of extra parameters. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address… |