Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.52% | — | Huawei Vmall | 22/11/2017 | 17/6/2026 | The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience. | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Small Business Sa520 FirmwareCisco Small Business Sa540 Firmware | 23/10/2017 | 17/6/2026 | Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files. | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Small Business IP Phone Firmware | 19/10/2017 | 17/6/2026 | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the… | |
| Modificada | Media (4.4) | 0.29% | — | Intel Active Management Technology FirmwareIntel Manageability Engine FirmwareIntel Small Business Technology Firmware | 5/9/2017 | 17/6/2026 | Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Small Business Rv340 FirmwareCisco Small Business Rv345 FirmwareCisco Small Business Rv345p Firmware | 17/8/2017 | 17/6/2026 | A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to Cisco WebEx Meetings not… | |
| Modificada | Crítica (9.6) | 1.8% | — | Cisco Small Business RV Router FirmwareCisco Small Business RV Router Firmware 1.0 | 16/5/2017 | 17/6/2026 | A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability… | |
| Modificada | Media (5.8) | 1.6% | — | Cisco Small Business RV Series Router Firmware | 3/5/2017 | 17/6/2026 | A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request… | |
| Modificada | Media (5.5) | 5.3% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Media (5.5) | 6.9% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Alta (7.5) | 2.2% | — | Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+4 | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,… | |
| Modificada | Media (5.3) | 4.3% | 💥 PoC | Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+4 | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,… | |
| Modificada | Crítica (9.8) | 4.0% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216. | |
| Modificada | Alta (7.5) | 2.9% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238. | |
| Modificada | Media (6.1) | 1.5% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232. | |
| Modificada | Alta (8.8) | 0.97% | — | Cisco Small Business 220 Series Smart Plus Switches | 2/9/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230. | |
| Modificada | Media (5.3) | 1.3% | — | Cisco Small Business Wireless Access Points Firmware | 17/2/2016 | 17/6/2026 | Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457. | |
| Modificada | Media (5.8) | 0.92% | — | Cisco Universal Small Cell Firmware | 15/2/2016 | 17/6/2026 | Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID… | |
| Modificada | Media (5.4) | 0.27% | — | Texasweddingmall Villa Antonia | 21/10/2014 | 17/6/2026 | The Villa Antonia (aka com.appbuilder.u7p5019) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Emartmall | 18/9/2014 | 17/6/2026 | The emartmall (aka kr.co.emart.emartmall) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Shinsegaemall Froyo | 15/9/2014 | 17/6/2026 | The froyo (aka com.shinsegae.mobile.froyo) application 5.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Cjmall | 9/9/2014 | 17/6/2026 | The CJmall (aka com.cjoshppingphone) application 4.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.3% | — | Cisco Universal Small Cell Series Firmware | 2/7/2014 | 17/6/2026 | The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Parallels Plesk PanelParallels Small Business Panel | 18/7/2013 | 16/6/2026 | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823. | |
| Modificada | Media (6.4) | 0.51% | — | Cisco Small Business Wireless Access Ppoints | 13/2/2013 | 16/6/2026 | Cisco Small Business Wireless Access Points WAP200, WAP2000, WAP200E, and WET200 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SSID that is not properly handled during a site survey, aka Bug IDs CSCua86182, CSCua91196, CSCud36155, and CSCua86190. | |
| Modificada | Media (4.3) | 1.3% | — | Nedprod Nedmalloc | 25/7/2012 | 16/6/2026 | Multiple integer overflows in the (1) CallMalloc (malloc) and (2) nedpcalloc (calloc) functions in nedmalloc (nedmalloc.c) before 1.10 beta2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than… |