Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)7.2%—Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+18/6/202017/6/2026
GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the…
ModificadaAlta (7.1)0.81%—Cisco Unified Contact Center Express3/6/202017/6/2026
A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability…
ModificadaCrítica (9.8)7.1%—Cisco Unified Contact Center Express22/5/202017/6/2026
A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An…
ModificadaMedia (4.3)0.68%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data6/5/202017/6/2026
A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect…
AnalizadaMedia (6.1)85%⚠ Explotación activa💥 ExploitJqueryDebian LinuxFedoraproject FedoraDrupal+4829/4/202017/6/2026
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7.5)1.8%—Prestashop Correos Express27/4/202017/6/2026
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.
ModificadaMedia (6.5)5.3%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.8)62%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)61%💥 ExploitCisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.5)24%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)74%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)76%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)88%💥 ExploitCisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.3)39%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (8.8)74%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data15/4/202017/6/2026
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.5)2.8%—Cisco Unified Communications ManagerCisco Unified Contact Center Express15/4/202017/6/2026
A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability…
ModificadaMedia (4.6)0.75%—Oracle Application Express15/4/202017/6/2026
Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful…
ModificadaAlta (7.8)1.00%💥 ExploitNchsoftware Express Invoice7/4/202017/6/2026
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
ModificadaAlta (8.8)2.2%—Nchsoftware Express Invoice7/4/202017/6/2026
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
ModificadaMedia (5.3)1.3%—Express-mock-middleware Project Express-mock-middleware7/4/202017/6/2026
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be…
ModificadaCrítica (9.8)1.2%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
ModificadaAlta (7.5)0.71%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
ModificadaAlta (8.1)0.84%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.
ModificadaMedia (6.1)4.3%—CkeditorFedoraproject FedoraDrupalOracle Agile Product Lifecycle Management+77/3/202025/8/2026
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
ModificadaMedia (5.9)0.60%—Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+367/2/202017/6/2026
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,…