Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.6% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an… | |
| Modificada | Media (5.4) | 0.55% | — | Alfresco Community ShareAlfresco Share | 21/10/2021 | 17/6/2026 | An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on the content… | |
| Modificada | Media (5.7) | 0.52% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 20/10/2021 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the… | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Payara Micro Community | 23/9/2021 | 17/6/2026 | Payara Micro Community 5.2021.6 and below allows Directory Traversal. | |
| Modificada | Media (5.4) | 0.81% | — | Invisioncommunity Invision Power Board | 17/8/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the… | |
| Modificada | Media (6.1) | 0.77% | — | Invisioncommunity Invision Power Board | 17/8/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function. | |
| Modificada | Media (6.1) | 0.83% | — | Community Events Project Community Events | 2/8/2021 | 17/6/2026 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 21/7/2021 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS… | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment | 12/7/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user. | |
| Modificada | Media (6.7) | 0.20% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment | 12/7/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user. | |
| Modificada | Media (6.7) | 0.19% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment | 12/7/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local authenticated Service user could potentially exploit this vulnerability to escalate privileges. | |
| Modificada | Alta (8.8) | 20% | — | Invisioncommunity IPS Community Suite | 1/6/2021 | 17/6/2026 | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method. | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Media (6.7) | 0.14% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 30/4/2021 | 17/6/2026 | Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerability when the Dell Upgrade Readiness Utility is run on the system. The credentials of the Unisphere Administrator are stored in plain text. A local malicious user with high privileges may use the… | |
| Modificada | Baja (3.5) | 0.72% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 22/4/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Modificada | Media (6.1) | 0.82% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence ServiceCisco Unity Connection | 8/4/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could… | |
| Modificada | Media (6.1) | 0.82% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence ServiceCisco Unity Connection | 8/4/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could… | |
| Modificada | Alta (8.8) | 2.7% | — | Cisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence ServiceCisco Unity Connection | 8/4/2021 | 17/6/2026 | A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to… | |
| Modificada | Media (4.3) | 1.3% | — | Canonical Unity-firefox-extensionCanonical Ubuntu Linux | 7/4/2021 | 16/6/2026 | The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in… | |
| Modificada | Media (6.5) | 1.3% | — | Canonical Unity-firefox-extensionCanonical Ubuntu Linux | 7/4/2021 | 16/6/2026 | The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the… | |
| Modificada | Alta (8.8) | 2.6% | — | Endian Firewall Community | 15/2/2021 | 17/6/2026 | Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment. | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express Opportunity Tracker | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Emergency ResponderCisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 13/1/2021 | 17/6/2026 | A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an… | |
| Modificada | Alta (8.8) | 1.4% | — | Invisioncommunity IPS Community Suite | 8/1/2021 | 17/6/2026 | Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php). | |
| Modificada | Media (6.1) | 0.64% | — | Invisioncommunity IPS Community Suite | 5/1/2021 | 17/6/2026 | Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. |