Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

535 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.95%—Dell Unity Operating Environment12/2/202417/6/2026
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.
ModificadaAlta (7.8)1.1%—Dell Unity Operating Environment12/2/202417/6/2026
Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.
ModificadaMedia (4.8)0.35%—Cisco Unity Connection26/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied…
ModificadaCrítica (10)2.4%—Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+126/1/202417/6/2026
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could…
ModificadaMedia (4.3)0.30%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment24/1/202417/6/2026
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also…
ModificadaCrítica (9.8)1.6%—Cisco Unity Connection17/1/202417/6/2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of authentication in a specific API and improper…
ModificadaAlta (7.5)0.62%—Steve-community Ocpp-jaxb26/12/202317/6/2026
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine…
ModificadaMedia (6.1)0.49%—Communitydeveloper Amazzing Filter28/11/202317/6/2026
Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code.
ModificadaMedia (5.9)0.29%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment22/11/202317/6/2026
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.
ModificadaCrítica (9.8)0.81%—Johnsoncontrols Quantum HD Unity Compressor FirmwareJohnsoncontrols Quantum HD Unity Acuair FirmwareJohnsoncontrols Quantum HD Unity Condenser/vessel FirmwareJohnsoncontrols Quantum HD Unity Evaporator Firmware+210/11/202317/6/2026
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
ModificadaCrítica (9.8)1.2%💥 PoCUvdesk Community-skeleton23/10/202317/6/2026
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
ModificadaMedia (6.5)0.44%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment23/10/202317/6/2026
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.
ModificadaAlta (7.8)0.18%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment23/10/202317/6/2026
Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands.
ModificadaAlta (7.5)0.47%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment23/10/202317/6/2026
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.
ModificadaMedia (5.4)0.29%—Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment23/10/202317/6/2026
Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges.
ModificadaMedia (5.3)1.2%💥 PoCKoha-community Koha Library Software11/10/202317/6/2026
File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.
ModificadaAlta (7.5)1.4%—Koha-community Koha Library Software11/10/202317/6/2026
SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.
ModificadaAlta (7.5)0.81%—Cisco Emergency ResponderCisco Prime Collaboration DeploymentCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+14/10/202317/6/2026
A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is…
ModificadaAlta (7.2)0.49%—Cisco Emergency ResponderCisco Unified Communications ManagerCisco Unity Connection30/8/202317/6/2026
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This…
ModificadaAlta (7)0.30%💥 PoCUnity Parsec20/8/202317/6/2026
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader…
ModificadaMedia (6.5)0.59%—Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+419/4/202317/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
ModificadaAlta (7.5)0.62%—Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+319/4/202317/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
ModificadaMedia (6.1)0.69%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket.
ModificadaAlta (8.8)1.6%—Uvdesk Community-skeleton4/4/202317/6/2026
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers.
ModificadaMedia (4.8)0.39%—Community Events Project Community Events23/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.