Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

535 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.7%—Unity3d Unity Editor31/12/201917/6/2026
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
ModificadaMedia (6.5)0.19%—Philips Veradius Unity FirmwarePhilips Pulsera FirmwarePhilips Endura Firmware20/12/201917/6/2026
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped…
ModificadaBaja (3.3)0.32%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server6/12/201916/6/2026
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
ModificadaMedia (6.7)0.40%—Cisco Unity Express26/11/201917/6/2026
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator credentials. The vulnerability is due to improper input validation for certain…
ModificadaMedia (6.5)0.67%—Cisco Unified Communications ManagerCisco Unity ConnectionCisco Unified Communications Manager IM AND Presence Service2/10/201917/6/2026
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to…
ModificadaMedia (6.1)1.1%—Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection2/10/201917/6/2026
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of…
ModificadaMedia (4.9)1.7%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
ModificadaMedia (6.1)0.82%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
ModificadaAlta (7.2)1.8%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
ModificadaCrítica (9.8)1.5%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
ModificadaMedia (5.3)1.5%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.
ModificadaAlta (7.5)1.8%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.
ModificadaAlta (8.8)0.61%—Silver-peak Unity Edgeconnect Sd-wan Firmware8/9/201917/6/2026
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
ModificadaMedia (6.1)1.1%—Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating EnvironmentDell EMC Vnxe3200 Firmware3/9/201917/6/2026
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this…
ModificadaMedia (6.5)0.88%—Unity WEB Player29/7/201917/6/2026
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
ModificadaAlta (7.8)0.34%—Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment18/7/201917/6/2026
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the…
ModificadaMedia (4.3)1.1%—Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment18/7/201917/6/2026
Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator could potentially exploit this vulnerability to edit quota configuration of other users.
ModificadaMedia (5.3)0.88%—Unity822/4/201917/6/2026
In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.
ModificadaAlta (7.8)0.43%—Ubports Unity822/4/201917/6/2026
Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.
ModificadaMedia (6.1)1.9%—Invisioncommunity Invision Power Board2/3/201917/6/2026
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
ModificadaMedia (6.1)1.2%—Cisco Unity Connection21/2/201917/6/2026
A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability is due to insufficient…
ModificadaAlta (7.8)0.43%—Liquidware FlexappLiquidware Profileunity21/2/201917/6/2026
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
ModificadaBaja (3.1)1.1%—Oracle Peoplesoft Enterprise Campus Software Campus Community16/1/201917/6/2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). Supported versions that are affected are 9.0 and 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS…
ModificadaCrítica (9.8)87%—Cisco Unity Express8/11/201817/6/2026
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit…
ModificadaMedia (6.1)0.87%—Telligent Community23/10/201817/6/2026
Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 has XSS via the Feed RSS widget.
Orbitaley — Vulnerabilidades