Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
739 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Auth0 Express-jwt | 30/6/2020 | 17/6/2026 | In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of… | |
| Modificada | Alta (8.8) | 0.58% | — | Cabsoftware Reportexpress Proplus | 29/6/2020 | 17/6/2026 | Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). | |
| Modificada | Alta (8.8) | 4.1% | — | Expressionengine | 24/6/2020 | 17/6/2026 | ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new… | |
| Modificada | Media (6.1) | 0.64% | — | Microfocus Arcsight Enterprise Security Manager Express | 16/6/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, Affecting versions 7.0.x, 7.2 and 7.2.1 . The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS) or information disclosure. | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Alta (7.1) | 0.81% | — | Cisco Unified Contact Center Express | 3/6/2020 | 17/6/2026 | A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability… | |
| Modificada | Crítica (9.8) | 7.1% | — | Cisco Unified Contact Center Express | 22/5/2020 | 17/6/2026 | A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An… | |
| Modificada | Media (4.3) | 0.68% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 6/5/2020 | 17/6/2026 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect… | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.5) | 1.8% | — | Prestashop Correos Express | 27/4/2020 | 17/6/2026 | The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers. | |
| Modificada | Media (6.5) | 5.3% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 62% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 61% | 💥 Exploit | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.5) | 24% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 74% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 76% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 88% | 💥 Exploit | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.3) | 39% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 74% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 15/4/2020 | 17/6/2026 | Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco Unified Communications ManagerCisco Unified Contact Center Express | 15/4/2020 | 17/6/2026 | A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability… | |
| Modificada | Media (4.6) | 0.75% | — | Oracle Application Express | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful… | |
| Modificada | Alta (7.8) | 1.00% | 💥 Exploit | Nchsoftware Express Invoice | 7/4/2020 | 17/6/2026 | NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. | |
| Modificada | Alta (8.8) | 2.2% | — | Nchsoftware Express Invoice | 7/4/2020 | 17/6/2026 | In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. | |
| Modificada | Media (5.3) | 1.3% | — | Express-mock-middleware Project Express-mock-middleware | 7/4/2020 | 17/6/2026 | express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be… | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. |