Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.65% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | |
| Modificada | Crítica (9.6) | 1.4% | — | Cisco Unified Contact Center ExpressCisco Unified Contact Center Management Portal | 14/1/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote attacker to elevate their privileges to Administrator. This vulnerability is due to the lack of… | |
| Modificada | Crítica (9.8) | 1.1% | — | Baxter Welch Allyn Connex CardioBaxter Welch Allyn Diagnostic Cardiology SuiteBaxter Welch Allyn Rscribe Resting ECG SystemBaxter Welch Allyn Vision Express Holter Analysis System+3 | 15/12/2021 | 17/6/2026 | The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 0.92% | — | Auth0 Express Openid Connect | 9/12/2021 | 17/6/2026 | Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions… | |
| Modificada | Crítica (9.8) | 1.6% | — | Tripexpress Project Tripexpress | 29/11/2021 | 17/6/2026 | tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability. | |
| Modificada | Media (5.4) | 1.6% | — | CkeditorDrupalOracle Agile Product Lifecycle ManagementOracle Application Express+5 | 17/11/2021 | 17/6/2026 | CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing… | |
| Modificada | Media (5.4) | 1.3% | — | CkeditorDrupalOracle Banking ApisOracle Banking Digital Experience+6 | 17/11/2021 | 25/8/2026 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing… | |
| Modificada | Crítica (9.8) | 1.3% | — | Tibco Partnerexpress | 16/11/2021 | 17/6/2026 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human… | |
| Modificada | Crítica (9) | 0.99% | — | Tibco Partnerexpress | 16/11/2021 | 17/6/2026 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the… | |
| Modificada | Alta (8.8) | 1.0% | — | Tibco Partnerexpress | 16/11/2021 | 17/6/2026 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain session tokens for the affected system. A successful attack using this vulnerability requires human… | |
| Modificada | Alta (7.8) | 0.65% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 4/11/2021 | 17/6/2026 | Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory. | |
| Modificada | Alta (7.5) | 0.99% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via… | |
| Modificada | Alta (7.5) | 1.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | |
| Modificada | Alta (7.5) | 1.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code… | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.2% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Crítica (9.8) | 2.1% | — | NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe | 3/11/2021 | 17/6/2026 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network. | |
| Modificada | Media (6.1) | 41% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+23 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A… | |
| Modificada | Media (6.1) | 8.5% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+24 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as… | |
| Modificada | Media (6.1) | 39% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H500s FirmwareNetapp H700s Firmware+25 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS… | |
| Modificada | Media (4.8) | 0.62% | — | Expresstech Quiz AND Survey Master | 11/10/2021 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |