Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Asus Ipswcom Activex ComponentAsus Net4switch | 15/9/2012 | 16/6/2026 | Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method. | |
| Modificada | Media (4.3) | 2.0% | — | Mark Theunissen Views Lang Switch | 5/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Baja (3.6) | 0.35% | — | Openvswitch | 7/8/2012 | 16/6/2026 | Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files. | |
| Modificada | Alta (10) | 2.6% | — | Smc8024l2 Switch | 19/7/2012 | 16/6/2026 | The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, (8) dot1x/, (9) security/, (10) igmps/, or (11) snmp/. | |
| Modificada | Alta (7.8) | 1.8% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+11 | 12/7/2012 | 16/6/2026 | The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP… | |
| Modificada | Alta (8.3) | 1.7% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint SwitchCisco Telepresence System SoftwareCisco Telepresence System 1300 65+11 | 12/7/2012 | 16/6/2026 | The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Nx-osCisco Nexus 2148t FEX SwitchCisco Nexus 2224tp FEX SwitchCisco Nexus 2232pp FEX Switch+8 | 3/5/2012 | 16/6/2026 | Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682. | |
| Modificada | Baja (3.7) | 1.2% | — | HP Procurve Switch 5400zlHP Procurve Switch 5400zl Management ModuleHP Procurve Switch 5406-44g-poe+-4sfpzlHP Procurve Switch 5406-48gzl+10 | 12/4/2012 | 16/6/2026 | HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card. | |
| Modificada | Media (5) | 3.1% | — | Lg-nortel ELO Gs24m Switch | 22/3/2012 | 16/6/2026 | The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext credential and configuration information, via a direct request to a configuration web page. | |
| Modificada | Media (5) | 1.2% | — | Typo3 Beuserswitch | 14/2/2012 | 16/6/2026 | Unspecified vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Typo3 Beuserswitch | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.6% | — | Brocade Bigiron RX Switch | 17/7/2011 | 16/6/2026 | Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet. | |
| Modificada | Media (6.8) | 3.2% | — | Ipswitch Imail | 16/3/2011 | 16/6/2026 | The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command… | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Telepresence Recording Server SoftwareCisco Telepresence Recording ServerCisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption… | |
| Modificada | Alta (8) | 2.0% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to a servlet, aka Bug ID CSCtf97164. | |
| Modificada | Alta (10) | 5.2% | — | Cisco Telepresence Recording Server SoftwareCisco Telepresence Recording ServerCisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitrary files, and possibly execute arbitrary code, via a crafted… | |
| Modificada | Alta (10) | 5.9% | — | Cisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253. | |
| Modificada | Alta (10) | 6.5% | — | Cisco Telepresence Recording Server SoftwareCisco Telepresence Recording ServerCisco Telepresence Multipoint Switch SoftwareCisco Telepresence Multipoint Switch | 25/2/2011 | 16/6/2026 | The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to… | |
| Modificada | Alta (7.9) | 2.1% | — | Cisco Adaptive Security Appliance SoftwareCisco 5500 Series Adaptive Security ApplianceCisco ASA 5500Cisco Telepresence Multipoint Switch Software+9 | 25/2/2011 | 16/6/2026 | Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x,… | |
| Modificada | Media (6.1) | 0.89% | — | HP Procurve Switch SoftwareHP Procurve Switch 2610HP Procurve Switch 2610-24HP Procurve Switch 2610-24-pwr+3 | 9/8/2010 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve 2610 switch before R.11.22, when DHCP is enabled, allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (8.3) | 1.2% | — | HP Procurve Switch SoftwareHP Procurve Switch 2626HP Procurve Switch 2626-pwrHP Procurve Switch 2650+1 | 9/8/2010 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve 2626 and 2650 switches before H.10.80 allows remote attackers to obtain sensitive information, modify data, and cause a denial of service via unknown vectors. | |
| Modificada | Media (6.1) | 0.89% | — | HP Procurve Switch SoftwareHP Procurve Switch 2610HP Procurve Switch 2610-24HP Procurve Switch 2610-24-pwr+3 | 9/8/2010 | 16/6/2026 | Unspecified vulnerability in the In-band Agent on the HP ProCurve 2610 switch before R.11.30 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (6.1) | 0.98% | — | HP Procurve Switch SoftwareHP Procurve Switch 1800-24gHP Procurve Switch 1800-8g | 9/8/2010 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve 1800-24G switch with software PB.03.02 and earlier, and the ProCurve 1800-8G switch with software PA.03.02 and earlier, when SNMP is enabled, allows remote attackers to obtain sensitive information via unknown vectors. |