Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Invisioncommunity Invision Power Board | 11/5/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user… | |
| Modificada | Media (5.3) | 2.5% | — | Cisco Unity Connection | 3/5/2017 | 17/6/2026 | A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An… | |
| Modificada | Media (6.5) | 1.7% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 24/4/2017 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus… | |
| Modificada | Media (5.9) | 1.3% | — | Invisioncommunity Invision Power Board | 23/4/2017 | 17/6/2026 | Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation. | |
| Modificada | Alta (7) | 1.1% | — | Schneider-electric Unity PRO | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the… | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | Invisioncommunity Invision Power BoardPHP | 12/7/2016 | 17/6/2026 | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter. | |
| Modificada | Alta (7.5) | 8.3% | — | Cisco IOS XECisco Webex Meeting CenterCisco DX Series IP Phones FirmwareCisco IP Phone 7800 Series Firmware+10 | 21/4/2016 | 17/6/2026 | The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unity Connection | 12/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unity Connection | 30/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux82596. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Unity Connection | 27/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582. | |
| Modificada | Media (6.8) | 0.98% | — | Cisco Unity Connection | 12/12/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux24578. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Unity Connection | 3/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741. | |
| Modificada | Media (4) | 1.1% | — | Tibco Loglogic Unity | 18/11/2015 | 17/6/2026 | The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request. | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Unity Connection | 20/9/2015 | 17/6/2026 | SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824. | |
| Modificada | Alta (7.8) | 1.4% | — | Invisioncommunity Invision Power Board | 4/9/2015 | 17/6/2026 | Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL. | |
| Modificada | Media (6.8) | 0.82% | — | Cisco Unity Connection | 7/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Unity Connection | 7/5/2015 | 17/6/2026 | SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608. | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Unity Connection | 3/4/2015 | 17/6/2026 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) by improperly terminating SIP TCP connections,… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Unity Connection | 3/4/2015 | 17/6/2026 | The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Unity Connection | 3/4/2015 | 17/6/2026 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Unity Connection | 3/4/2015 | 17/6/2026 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Unity ConnectionCisco Unity Connection 8.5Cisco Unity Connection 8.6 | 3/4/2015 | 17/6/2026 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU6, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (SIP outage) via a crafted UDP packet, aka Bug ID CSCuh25062. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Wotlab Community Gallery | 12/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy. | |
| Modificada | Media (4) | 1.3% | — | Topline Systems Opportunity Form | 16/2/2015 | 17/6/2026 | Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.6% | — | Schneider-electric SomachineSchneider-electric SomoveSchneider-electric Somove LiteSchneider-electric Unity PRO | 1/2/2015 | 17/6/2026 | Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB… |