Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.46%—Smoothwall Express7/2/202016/6/2026
CSRF vulnerability in Smoothwall Express 3.
ModificadaMedia (6.1)0.65%—Smoothwall Express7/2/202016/6/2026
A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.
ModificadaCrítica (9.8)2.9%—Netvu Dv-ip Express FirmwareNetvu Sd-advanced - Sdhd FirmwareNetvu Sd-advanced 8/12/16 VGA FirmwareNetvu SD Advanced Closed Iptv (m3u) Firmware+166/2/202017/6/2026
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The…
ModificadaMedia (6.1)0.90%—Cisco FinesseCisco Unified Contact Center Express26/1/202017/6/2026
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could…
ModificadaAlta (8.8)2.4%—Peerigon Angular-expressions24/1/202017/6/2026
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-expressions in the browser, an attacker could run any browser script when the application code calls…
ModificadaMedia (6.1)0.78%—Lifesize Express 220 FirmwareLifesize Room 220i Firmware22/1/202017/6/2026
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
AnalizadaCrítica (9.9)85%⚠ Explotación activa💥 ExploitMongo-express Project Mongo-express24/12/201917/6/2026
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
ModificadaMedia (6.1)1.7%—Expresstech Quiz AND Survey Master13/12/201917/6/2026
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php.…
ModificadaMedia (6.7)0.40%—Cisco Unity Express26/11/201917/6/2026
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator credentials. The vulnerability is due to improper input validation for certain…
ModificadaMedia (5.3)1.4%—Mitel MicollabMitel Mivoice Business Express12/11/201917/6/2026
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1 (8.0.2.202), could allow creation of unauthorized…
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (7.8)3.3%—Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express31/10/201917/6/2026
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to…
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (5.4)0.58%—Nchsoftware Express Accounts Accounting17/10/201917/6/2026
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript.
ModificadaMedia (5.4)0.58%—Nchsoftware Express Invoice14/10/201917/6/2026
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
ModificadaMedia (6.1)1.1%—Cisco Unified Contact Center Express2/10/201917/6/2026
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could…
ModificadaAlta (7.5)1.5%—Cisco Unified Contact Center Express5/9/201917/6/2026
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An…
ModificadaMedia (5.4)0.79%—Bitwise-it Webp Express30/8/201917/6/2026
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
ModificadaAlta (7.5)1.8%—Webp Express Project Webp Express22/8/201917/6/2026
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
ModificadaCrítica (9.8)4.5%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is…
ModificadaCrítica (9.8)4.6%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper…
ModificadaCrítica (9.8)76%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user…
ModificadaAlta (7.2)39%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of…
ModificadaCrítica (9.8)83%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The…
ModificadaAlta (7.5)2.0%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing…
Orbitaley — Vulnerabilidades