Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.52%—Huawei Vmall22/11/201717/6/2026
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
ModificadaAlta (7.5)2.2%—Cisco Small Business Sa520 FirmwareCisco Small Business Sa540 Firmware23/10/201717/6/2026
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
ModificadaAlta (7.5)2.3%—Cisco Small Business IP Phone Firmware19/10/201717/6/2026
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the…
ModificadaMedia (4.4)0.29%—Intel Active Management Technology FirmwareIntel Manageability Engine FirmwareIntel Small Business Technology Firmware5/9/201717/6/2026
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative…
ModificadaMedia (5.3)1.7%—Cisco Small Business Rv340 FirmwareCisco Small Business Rv345 FirmwareCisco Small Business Rv345p Firmware17/8/201717/6/2026
A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to Cisco WebEx Meetings not…
ModificadaCrítica (9.6)1.8%—Cisco Small Business RV Router FirmwareCisco Small Business RV Router Firmware 1.016/5/201717/6/2026
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability…
ModificadaMedia (5.8)1.6%—Cisco Small Business RV Series Router Firmware3/5/201717/6/2026
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request…
ModificadaMedia (5.5)5.3%💥 ExploitBroadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+1114/4/201717/6/2026
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaMedia (5.5)6.9%💥 ExploitBroadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+1114/4/201717/6/2026
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaAlta (7.5)2.2%—Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+413/2/201717/6/2026
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,…
ModificadaMedia (5.3)4.3%💥 PoCSchneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+413/2/201717/6/2026
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,…
ModificadaCrítica (9.8)4.0%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216.
ModificadaAlta (7.5)2.9%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238.
ModificadaMedia (6.1)1.5%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232.
ModificadaAlta (8.8)0.97%—Cisco Small Business 220 Series Smart Plus Switches2/9/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230.
ModificadaMedia (5.3)1.3%—Cisco Small Business Wireless Access Points Firmware17/2/201617/6/2026
Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.
ModificadaMedia (5.8)0.92%—Cisco Universal Small Cell Firmware15/2/201617/6/2026
Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID…
ModificadaMedia (5.4)0.27%—Texasweddingmall Villa Antonia21/10/201417/6/2026
The Villa Antonia (aka com.appbuilder.u7p5019) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Emartmall18/9/201417/6/2026
The emartmall (aka kr.co.emart.emartmall) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Shinsegaemall Froyo15/9/201417/6/2026
The froyo (aka com.shinsegae.mobile.froyo) application 5.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Cjmall9/9/201417/6/2026
The CJmall (aka com.cjoshppingphone) application 4.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)1.3%—Cisco Universal Small Cell Series Firmware2/7/201417/6/2026
The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513.
ModificadaAlta (7.5)31%💥 ExploitParallels Plesk PanelParallels Small Business Panel18/7/201316/6/2026
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.
ModificadaMedia (6.4)0.51%—Cisco Small Business Wireless Access Ppoints13/2/201316/6/2026
Cisco Small Business Wireless Access Points WAP200, WAP2000, WAP200E, and WET200 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SSID that is not properly handled during a site survey, aka Bug IDs CSCua86182, CSCua91196, CSCud36155, and CSCua86190.
ModificadaMedia (4.3)1.3%—Nedprod Nedmalloc25/7/201216/6/2026
Multiple integer overflows in the (1) CallMalloc (malloc) and (2) nedpcalloc (calloc) functions in nedmalloc (nedmalloc.c) before 1.10 beta2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than…