Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.58% | — | Nchsoftware Express Invoice | 14/10/2019 | 17/6/2026 | In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript. | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Contact Center Express | 2/10/2019 | 17/6/2026 | A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Unified Contact Center Express | 5/9/2019 | 17/6/2026 | A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An… | |
| Modificada | Media (5.4) | 0.79% | — | Bitwise-it Webp Express | 30/8/2019 | 17/6/2026 | The webp-express plugin before 0.14.8 for WordPress has stored XSS. | |
| Modificada | Alta (7.5) | 1.8% | — | Webp Express Project Webp Express | 22/8/2019 | 17/6/2026 | The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. | |
| Modificada | Crítica (9.8) | 4.5% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is… | |
| Modificada | Crítica (9.8) | 4.6% | — | Cisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper… | |
| Modificada | Crítica (9.8) | 76% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user… | |
| Modificada | Alta (7.2) | 39% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of… | |
| Modificada | Crítica (9.8) | 83% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing… | |
| Modificada | Media (4.8) | 0.80% | — | Cisco Unified Contact Center Express | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to… | |
| Modificada | Alta (8.8) | 0.65% | — | Expresstech Responsive Menu | 14/8/2019 | 17/6/2026 | The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Media (6.5) | 0.69% | — | Cisco Expressway SeriesCisco Telepresence Video Communication Server | 18/4/2019 | 17/6/2026 | A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient… | |
| Modificada | Alta (8.8) | 1.2% | — | Express-cart Project Express-cart | 1/2/2019 | 17/6/2026 | A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators. | |
| Modificada | Alta (7.8) | 0.80% | — | MNC Inplc-rt SDK ExpressMNC Inplc SDK Pro+ | 9/1/2019 | 17/6/2026 | Untrusted search path vulnerability in Installer of INplc SDK Express 3.08 and earlier and Installer of INplc SDK Pro+ 3.08 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.1) | 0.61% | — | Expressvpn | 2/1/2019 | 17/6/2026 | An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over HTTP is used for communication. The… | |
| Modificada | Crítica (9.8) | 87% | — | Cisco Unity Express | 8/11/2018 | 17/6/2026 | A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit… | |
| Modificada | Media (6.1) | 0.65% | — | Expressionengine | 1/10/2018 | 17/6/2026 | ExpressionEngine before 4.3.5 has reflected XSS. | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040. | |
| Modificada | Alta (8.8) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967. | |
| Modificada | Media (6.1) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904. |