Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.80%—Cisco Unified Contact Center Express21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to…
ModificadaAlta (8.8)0.65%—Expresstech Responsive Menu14/8/201917/6/2026
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaMedia (6.5)0.69%—Cisco Expressway SeriesCisco Telepresence Video Communication Server18/4/201917/6/2026
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient…
ModificadaAlta (8.8)1.2%—Express-cart Project Express-cart1/2/201917/6/2026
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
ModificadaAlta (7.8)0.80%—MNC Inplc-rt SDK ExpressMNC Inplc SDK Pro+9/1/201917/6/2026
Untrusted search path vulnerability in Installer of INplc SDK Express 3.08 and earlier and Installer of INplc SDK Pro+ 3.08 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.1)0.61%—Expressvpn2/1/201917/6/2026
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over HTTP is used for communication. The…
ModificadaCrítica (9.8)87%—Cisco Unity Express8/11/201817/6/2026
A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit…
ModificadaMedia (6.1)0.65%—Expressionengine1/10/201817/6/2026
ExpressionEngine before 4.3.5 has reflected XSS.
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaCrítica (9.8)2.6%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
ModificadaAlta (8.8)1.0%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
ModificadaMedia (6.1)1.3%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
ModificadaAlta (7.8)33%💥 PoCMicrosoft Expression BlendMicrosoft Visual StudioMicrosoft Visual Studio 201711/7/201817/6/2026
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
ModificadaAlta (8.8)1.9%—Expresscart Project Expresscart15/6/201817/6/2026
expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
ModificadaAlta (8.8)27%—Express-cart Project Express-cart7/6/201817/6/2026
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
ModificadaAlta (7.5)2.0%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+97/6/201817/6/2026
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain…
ModificadaAlta (7.5)1.2%—Expressjs Method-override7/6/201817/6/2026
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the…
ModificadaAlta (8.8)1.4%—Express-restify-mongoose Project Express-restify-mongoose31/5/201817/6/2026
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the…
ModificadaAlta (7.5)2.2%—Cisco Mobility Express Software2/5/201817/6/2026
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The…
ModificadaMedia (6.1)1.1%—Oracle Application Express18/1/201817/6/2026
Vulnerability in the Application Express component of Oracle Database Server. The supported version that is affected is Prior to 5.1.4.00.08. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express. Successful attacks require human interaction…
ModificadaMedia (5.4)0.51%—Expressionengine17/11/201717/6/2026
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
ModificadaCrítica (9.8)6.4%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+716/11/201717/6/2026
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration…
ModificadaAlta (7.8)0.32%—Cisco Identity Services EngineCisco Identity Services Engine ExpressCisco Identity Services Engine Virtual Appliance2/11/201717/6/2026
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the…
Orbitaley — Vulnerabilidades