Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
301 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.4% | 💥 Exploit | Mitel Connect Onsite | 6/3/2019 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Mitel Connect Onsite | 6/3/2019 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Mitel Connect Onsite | 6/3/2019 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Mitel Mivoice Office 400 | 23/10/2018 | 17/6/2026 | A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to… | |
| Modificada | Crítica (9.8) | 4.9% | — | Mitel Mivoice 5330e Firmware | 23/10/2018 | 17/6/2026 | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution. | |
| Modificada | Media (6.1) | 1.1% | — | Mitel ST Firmware | 23/10/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute… | |
| Modificada | Alta (7.5) | 0.44% | — | Mitel Shortel Mobility Client | 13/7/2018 | 17/6/2026 | On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to obtain sensitive account information such as login credentials. | |
| Modificada | Alta (7.5) | 1.1% | — | Hormitechtoken Project Hormitechtoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for HormitechToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Modificada | Media (6.5) | 1.1% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the signin… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Modificada | Crítica (9.8) | 1.5% | — | Keepsolid VPN Unlimited | 16/3/2018 | 17/6/2026 | VPN Unlimited 4.2.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Mitel Connect OnsiteMitel St14.2 | 14/3/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to… | |
| Modificada | Crítica (9.8) | 1.7% | — | Mitel Connect OnsiteMitel St14.2 | 14/3/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page. Successful exploit could allow an attacker to… | |
| Modificada | Crítica (9.8) | 1.7% | — | Mitel Connect OnsiteMitel St14.2 | 14/3/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vnewmeeting.php page. Successful exploit could allow an attacker to… | |
| Modificada | Crítica (9.8) | 2.7% | — | Mitel Connect OnsiteMitel St14.2 | 14/3/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests.… | |
| Modificada | Alta (8.8) | 1.8% | — | Mitel St14.2 | 13/3/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execute arbitrary code within the context of the application. | |
| Modificada | Media (5.3) | 0.85% | — | Mitel St14.2 | 13/3/2018 | 17/6/2026 | A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names. | |
| Modificada | Crítica (9.8) | 25% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors. | |
| Modificada | Crítica (9.4) | 4.3% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature." | |
| Modificada | Crítica (9.4) | 64% | 💥 Exploit | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Fpinternet Texas Poker Unlimited Hold'em | 20/10/2014 | 17/6/2026 | The Texas Poker Unlimited Hold'em (aka com.fpinternet.texaspokerunlimitedholdem) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Whoisit Who-is-it? Lite Name Caller Time Limited Free | 16/10/2014 | 17/6/2026 | The Who-is-it? Lite name caller time limited free (aka de.profiler.android.whoisit) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |