Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

8750 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.64%—Cisco Unified Computing SystemCisco Unified Computing System E-series Software5/8/202616/9/2026
—
AnalizadaAlta (8.8)0.73%💥 PoCCisco Unified Computing System5/8/202631/8/2026
—
Pendiente de análisisMedia (4.8)0.29%—Cisco Integrated Management ControllerAI5/8/20266/8/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could…
AnalizadaAlta (7.7)0.50%—Cisco IOS XE5/8/202617/9/2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests.…
Pendiente de análisisMedia (5)0.35%—Cisco Terminal Service AgentAI5/8/20266/8/2026
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least…
AnalizadaAlta (8.6)0.47%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities…
ModificadaCrítica (9.8)0.57%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
ModificadaAlta (8.6)0.47%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
ModificadaAlta (8.6)0.47%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
ModificadaAlta (8.6)0.47%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
ModificadaAlta (8.6)0.47%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities…
ModificadaCrítica (9)0.38%—Cisco IOS XE5/8/20262/10/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
AnalizadaAlta (8.6)0.57%—Cisco IOS XE5/8/202628/9/2026
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker…
AplazadaBaja (2)0.33%—OscommerceAI3/8/202612/8/2026
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is…
AplazadaAlta (7.1)0.28%—Dynamic Pricing With Discount RulesAI1/8/202626/8/2026
The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user capabilities on one of its AJAX actions and reflects unsanitised user input in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is…
AnalizadaMedia (5.3)35%⚠ Explotación activaCisco Secure Firewall Management Center29/7/202616/9/2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
AplazadaAlta (7.1)0.25%—Wewoo Dynamic Pricing With Discount RulesAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
AplazadaMedia (5.1)0.31%—Milkdown Preset CommonmarkAITennisconnect ComponentsAI24/7/202627/7/2026
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The…
AplazadaAlta (8.1)0.46%—Miniorange Discord IntegrationAI23/7/202623/7/2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
AnalizadaCrítica (9.9)0.43%—Oracle Peoplesoft In-memory Project Discovery21/7/20266/8/2026
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.…
AplazadaMedia (5.3)0.40%—FreescoutAI20/7/202621/7/2026
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database overload and potential denial of service…
AplazadaCrítica (9.4)1.9%💥 ExploitFreescoutAI20/7/202621/7/2026
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then overwrites that account's email and password…
AplazadaMedia (4.9)0.53%—FreescoutAILaravelAI20/7/202621/7/2026
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then pass the resolved path to Laravel's download response. Prior to version…
AplazadaAlta (8.8)0.51%—FreescoutAI20/7/202621/7/2026
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload endpoint `POST /uploads/upload`…
AplazadaMedia (4.6)0.19%—FreescoutAI20/7/202621/7/2026
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matching the pattern `__proto__`. However, this mitigation is incomplete: it only…