Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
499 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148. | |
| Modificada | Media (4.3) | 1.2% | — | Netshinesoftware COM Netinvoice | 24/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the nBill (com_nbill) component 2.3.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the message parameter in an income action to administrator/index.php. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Simple Invoices | 28/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attackers to inject arbitrary web script or HTML via (1) the having parameter in a manage action to index.php; (2) the Email field in an Add User action; (3) the Customer Name field in an Add Customer… | |
| Modificada | Media (5.3) | 0.33% | — | Fortinet Fortigate-1000cFortinet Fortigate-100dFortinet Fortigate-110cFortinet Fortigate-1240b+25 | 14/11/2012 | 16/6/2026 | The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Fortinet_CA_SSLProxy certificate… | |
| Modificada | Alta (7.5) | 1.3% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477. | |
| Modificada | Alta (7.5) | 1.2% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+14 | 13/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,… | |
| Modificada | Alta (10) | 1.4% | — | Youmail Visual Voicemail Plus | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the YouMail Visual Voicemail Plus (com.youmail.android.vvm) application 2.0.45 and 2.1.43 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (7.8) | 26% | 💥 Exploit | Cisco Unified IP Interactive Voice ResponseCisco Unified IP IVRCisco Unified Communications Manager | 27/10/2011 | 16/6/2026 | Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x)… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Chillcreations COM Ccinvoices | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Netshinesoftware COM Netinvoice | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... the contents of an encrypted file." | |
| Modificada | Media (5) | 1.8% | — | Netshinesoftware COM Netinvoice | 17/11/2010 | 16/6/2026 | Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1)… | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+6 | 30/9/2010 | 16/6/2026 | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked… | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+9 | 21/9/2010 | 16/6/2026 | The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+11 | 8/9/2010 | 16/6/2026 | The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelVmware ESXAvaya Aura Communication ManagerAvaya Aura Presence Services+5 | 8/9/2010 | 16/6/2026 | Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295. | |
| Modificada | Alta (7.8) | 2.5% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message. | |
| Modificada | Media (5) | 9.1% | 💥 Exploit | Joomlart COM Javoice | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+14 | 16/11/2009 | 16/6/2026 | The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | |
| Modificada | Alta (10) | 13% | — | Ciscoworks Common ServicesCiscoworks Health AND Utilization MonitorCiscoworks LAN Management SolutionCiscoworks QOS Policy Manager+6 | 21/5/2009 | 16/6/2026 | Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows… | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Cale Dunlap Openinvoice | 25/3/2009 | 16/6/2026 | resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Cale Dunlap Openinvoice | 25/3/2009 | 16/6/2026 | auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Netshinesoftware COM Netinvoice | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9) | 3.0% | — | Cisco Unified Customer Voice Portal | 22/5/2008 | 16/6/2026 | Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser account. |