Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Wap2 Smallpict19/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in SmallPICT.cgi in SmallPICT before 2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.1%—Cisco Small Business IP Phone FirmwareCisco Small Business IP Phone2/5/201216/6/2026
Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768.
ModificadaAlta (9)3.2%—Cisco Small Business Srp520 Series FirmwareCisco Small Business Srp521wCisco Small Business Srp526wCisco Small Business Srp527w+825/2/201216/6/2026
Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID…
ModificadaAlta (7.8)1.2%—Cisco Small Business Srp520 Series FirmwareCisco Small Business Srp521wCisco Small Business Srp526wCisco Small Business Srp527w+825/2/201216/6/2026
Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.
ModificadaAlta (9)2.2%—Cisco Small Business Srp520 Series FirmwareCisco Small Business Srp521wCisco Small Business Srp526wCisco Small Business Srp527w+825/2/201216/6/2026
The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.
ModificadaAlta (10)1.9%—Parallels Plesk Small Business Panel16/12/201116/6/2026
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving Wizard/Edit/Modules/Image and certain…
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as…
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js. NOTE: CVE disputes this issue because ASP is only used in a JavaScript comment
ModificadaMedia (4.3)0.97%—Parallels Plesk Small Business Panel16/12/201116/6/2026
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by…
ModificadaMedia (4.3)0.84%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Wizard/Edit/Modules/Image and certain other files.
ModificadaAlta (7.5)1.0%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/Edit/Html and certain other files.
ModificadaAlta (10)1.8%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ and certain other files. NOTE: it is possible that only clients, not…
ModificadaAlta (10)1.8%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuilder_edit.php and certain other files. NOTE: it is possible that only…
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by smb/email-address/list and certain other…
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs…
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and certain other files.
ModificadaAlta (10)2.2%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/auth and certain other files.
ModificadaMedia (5)1.1%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by domains/sitebuilder_edit.php and certain other…
ModificadaAlta (10)1.8%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to…
ModificadaMedia (4.3)0.84%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by smb/app/available/id/apscatalog/ and certain other files.
ModificadaAlta (7.5)1.0%—Parallels Plesk Small Business Panel16/12/201116/6/2026
Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by domains/sitebuilder_edit.php and certain other files.
ModificadaAlta (9.3)1.8%—Cisco Small Business Srp521wCisco Small Business Srp526wCisco Small Business Srp527wCisco Small Business Srp520 Series Firmware+43/11/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546W, and SRP547W with firmware before 1.2.1 allows remote attackers to hijack the…
ModificadaAlta (7.5)1.2%—Virtuenetz Virtue Shopping Mall8/10/201116/6/2026
SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
ModificadaMedia (5.8)1.2%—Wb-i Contents-mall13/1/201116/6/2026
Contents-Mall before 15 does not properly handle passwords, which allows remote attackers to discover the administrative password, and consequently obtain sensitive information or modify data, via unspecified vectors.
ModificadaMedia (4.3)1.0%—Netartmedia Iboutique.mall17/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.