Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.8% | — | Cisco Optical Networking Systems Software | 31/3/2003 | 16/6/2026 | Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet. | |
| Modificada | Media (5) | 1.4% | — | Cisco Optical Networking Systems Software | 31/3/2003 | 16/6/2026 | Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR). | |
| Modificada | Media (5) | 1.4% | — | Cisco Optical Networking Systems Software | 31/3/2003 | 16/6/2026 | Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character. | |
| Modificada | Media (5) | 1.6% | — | Cisco Optical Networking Systems Software | 31/3/2003 | 16/6/2026 | Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (4.6) | 0.36% | — | Cisco Optical Networking Systems Software | 31/3/2003 | 16/6/2026 | Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup. | |
| Modificada | Alta (10) | 4.1% | — | Sourcecraft Networking Utils | 31/12/2002 | 16/6/2026 | The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument. | |
| Modificada | Media (5) | 1.7% | — | Cisco Optical Networking Systems Software | 4/10/2002 | 16/6/2026 | Cisco ONS15454 optical transport platform running ONS 3.1.0 to 3.2.0 allows remote attackers to cause a denial of service (reset) by sending IP packets with non-zero Type of Service (TOS) bits to the Timing Control Card (TCC) LAN interface. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxAvaya CvlanAvaya Integrated Management SuitAvaya Interactive Response+3 | 31/12/2001 | 16/6/2026 | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. |