Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

301 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)4.4%💥 ExploitMitel Connect Onsite6/3/201917/6/2026
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaMedia (6.1)5.3%💥 ExploitMitel Connect Onsite6/3/201917/6/2026
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
ModificadaMedia (6.1)5.3%💥 ExploitMitel Connect Onsite6/3/201917/6/2026
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.
ModificadaMedia (6.1)1.1%—Mitel Mivoice Office 40023/10/201817/6/2026
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to…
ModificadaCrítica (9.8)4.9%—Mitel Mivoice 5330e Firmware23/10/201817/6/2026
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.
ModificadaMedia (6.1)1.1%—Mitel ST Firmware23/10/201817/6/2026
A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute…
ModificadaAlta (7.5)0.44%—Mitel Shortel Mobility Client13/7/201817/6/2026
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to obtain sensitive account information such as login credentials.
ModificadaAlta (7.5)1.1%—Hormitechtoken Project Hormitechtoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for HormitechToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaMedia (5.5)61%💥 ExploitIntel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaMedia (6.1)1.0%—Mitel Mivoice ConnectMitel ST 14.225/4/201817/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for…
ModificadaMedia (6.1)1.0%—Mitel Mivoice ConnectMitel ST 14.225/4/201817/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for…
ModificadaMedia (6.5)1.1%—Mitel Mivoice ConnectMitel ST 14.225/4/201817/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the signin…
ModificadaMedia (6.1)1.0%—Mitel Mivoice ConnectMitel ST 14.225/4/201817/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for…
ModificadaCrítica (9.8)1.5%—Keepsolid VPN Unlimited16/3/201817/6/2026
VPN Unlimited 4.2.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root.
ModificadaCrítica (9.8)19%💥 ExploitMitel Connect OnsiteMitel St14.214/3/201817/6/2026
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to…
ModificadaCrítica (9.8)1.7%—Mitel Connect OnsiteMitel St14.214/3/201817/6/2026
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page. Successful exploit could allow an attacker to…
ModificadaCrítica (9.8)1.7%—Mitel Connect OnsiteMitel St14.214/3/201817/6/2026
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vnewmeeting.php page. Successful exploit could allow an attacker to…
ModificadaCrítica (9.8)2.7%—Mitel Connect OnsiteMitel St14.214/3/201817/6/2026
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests.…
ModificadaAlta (8.8)1.8%—Mitel St14.213/3/201817/6/2026
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.
ModificadaMedia (5.3)0.85%—Mitel St14.213/3/201817/6/2026
A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names.
ModificadaCrítica (9.8)25%—Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited14/5/201617/6/2026
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.
ModificadaCrítica (9.4)4.3%—Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited14/5/201617/6/2026
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature."
ModificadaCrítica (9.4)64%💥 ExploitMeteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited14/5/201617/6/2026
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
ModificadaMedia (5.4)0.27%—Fpinternet Texas Poker Unlimited Hold'em20/10/201417/6/2026
The Texas Poker Unlimited Hold'em (aka com.fpinternet.texaspokerunlimitedholdem) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Whoisit Who-is-it? Lite Name Caller Time Limited Free16/10/201417/6/2026
The Who-is-it? Lite name caller time limited free (aka de.profiler.android.whoisit) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades