Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Primetek Primefaces | 13/3/2020 | 17/6/2026 | An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip title without any input validation. | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Prime Collaboration Provisioning | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Prime Collaboration Provisioning | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Alta (7.1) | 0.50% | — | Cisco Prime Network Registrar | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit… | |
| Modificada | Media (5.5) | 2.9% | — | Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+4 | 20/2/2020 | 17/6/2026 | Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform… | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Media (5.5) | 0.30% | — | Intel Quartus Prime | 16/12/2019 | 17/6/2026 | Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Quartus Prime | 16/12/2019 | 17/6/2026 | Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 3.3% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 26/11/2019 | 17/6/2026 | A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the… | |
| Modificada | Alta (7.8) | 0.31% | — | Samsung Galaxy J7 Prime Firmware | 14/11/2019 | 17/6/2026 | The Samsung j7popeltemtr Android device with a build fingerprint of samsung/j7popeltemtr/j7popeltemtr:8.1.0/M1AJQ/J727T1UVS5BSC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Prime Infrastructure | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Prime Infrastructure | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of… | |
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Media (6.5) | 1.3% | — | Cisco Prime Infrastructure | 20/6/2019 | 17/6/2026 | A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this… | |
| Modificada | Media (4.8) | 0.88% | — | Cisco Prime Service Catalog | 20/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Modificada | Alta (8.8) | 0.80% | — | Cisco Prime Service Catalog | 20/6/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection mechanisms on the web-based management… | |
| Modificada | Media (6.5) | 1.1% | — | Primeo Project Primeo | 19/6/2019 | 17/6/2026 | The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency. (Increasing the total supply by using… | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | MI Stock BrowserRedmi 7 FirmwareRedmi Note 7 FirmwareRedmi Note 6 PRO Firmware+15 | 7/6/2019 | 17/6/2026 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Quartus IIIntel Quartus Prime | 17/5/2019 | 17/6/2026 | Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.1) | 1.9% | — | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL… | |
| Modificada | Alta (8.1) | 1.9% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL… | |
| Modificada | Alta (7.2) | 4.4% | — | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Alta (7.2) | 4.4% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Crítica (9.8) | 98% | 💥 Exploit | Cisco Evolved Programmable Network ManagerCisco Network Level ServiceCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software… | |
| Modificada | Media (6.5) | 14% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 16/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization… |