Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.58%—Nchsoftware Express Invoice14/10/201917/6/2026
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
ModificadaMedia (6.1)1.1%—Cisco Unified Contact Center Express2/10/201917/6/2026
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could…
ModificadaAlta (7.5)1.5%—Cisco Unified Contact Center Express5/9/201917/6/2026
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An…
ModificadaMedia (5.4)0.79%—Bitwise-it Webp Express30/8/201917/6/2026
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
ModificadaAlta (7.5)1.8%—Webp Express Project Webp Express22/8/201917/6/2026
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
ModificadaCrítica (9.8)4.5%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is…
ModificadaCrítica (9.8)4.6%—Cisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper…
ModificadaCrítica (9.8)76%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user…
ModificadaAlta (7.2)39%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of…
ModificadaCrítica (9.8)83%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The…
ModificadaAlta (7.5)2.0%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing…
ModificadaMedia (4.8)0.80%—Cisco Unified Contact Center Express21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to…
ModificadaAlta (8.8)0.65%—Expresstech Responsive Menu14/8/201917/6/2026
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaMedia (6.5)0.69%—Cisco Expressway SeriesCisco Telepresence Video Communication Server18/4/201917/6/2026
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient…
ModificadaAlta (8.8)1.2%—Express-cart Project Express-cart1/2/201917/6/2026
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
ModificadaAlta (7.8)0.80%—MNC Inplc-rt SDK ExpressMNC Inplc SDK Pro+9/1/201917/6/2026
Untrusted search path vulnerability in Installer of INplc SDK Express 3.08 and earlier and Installer of INplc SDK Pro+ 3.08 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.1)0.61%—Expressvpn2/1/201917/6/2026
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over HTTP is used for communication. The…
ModificadaCrítica (9.8)87%—Cisco Unity Express8/11/201817/6/2026
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit…
ModificadaMedia (6.1)0.65%—Expressionengine1/10/201817/6/2026
ExpressionEngine before 4.3.5 has reflected XSS.
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaCrítica (9.8)2.6%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
ModificadaAlta (8.8)1.0%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
ModificadaMedia (6.1)1.3%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
Orbitaley — Vulnerabilidades