Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1092 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)4.5%⚠ Explotación activa💥 PoCCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection21/1/202617/6/2026
—
AplazadaMedia (6.9)0.42%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend.
AplazadaAlta (8.6)0.65%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaCrítica (9.3)0.50%—Browan Communications Prismx Mx100AI20/1/202617/6/2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.
AplazadaMedia (6.5)0.43%—Starnet Communications Corporation FastxAI14/10/202517/6/2026
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.
AplazadaAlta (7.2)0.24%—SSH Communications Security SSH Tectia ServerAI2/10/202517/6/2026
SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AplazadaCrítica (9.8)2.2%💥 ExploitSiklu Communications Etherhaul 8010txAISiklu Communications Etherhaul 1200fxAI15/9/20255/7/2026
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary. These keys are identical across all devices, allowing…
AnalizadaAlta (8.8)0.18%—Cisco Unified Communications Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This…
AnalizadaMedia (6.1)0.25%—Cisco Unified Communications Manager IM AND Presence Service3/9/20251/10/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based…
AplazadaCrítica (9.8)0.71%💥 PoCRingcentral CommunicationsAI28/8/202517/6/2026
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.
AplazadaAlta (8.7)1.1%—Spon Communications IP Network Broadcast SystemAI27/8/202517/6/2026
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory…
AnalizadaCrítica (10)1.2%—Cisco Unified Communications Manager2/7/202517/6/2026
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed…
AnalizadaMedia (6.7)0.18%—Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+44/6/202517/6/2026
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An…
AplazadaMedia (5.1)0.14%—Cisco Unified Communications AND Contact Center SolutionsAI21/5/202517/6/2026
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit…
AnalizadaMedia (5.5)0.20%—Oracle Communications Order AND Service Management15/4/202517/6/2026
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.8)0.14%—IBM Personal Communications8/4/202517/6/2026
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged…
AplazadaCrítica (9.3)0.52%—Carrcommunications RsvpmakerAI1/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7.
AplazadaMedia (5.3)0.29%—Carrcommunications RsvpmakerAI27/1/202517/6/2026
Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5.
AnalizadaMedia (5.3)0.38%—Oracle Communications Order AND Service Management21/1/202517/6/2026
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…
AnalizadaMedia (5.4)0.26%—Oracle Communications Order AND Service Management21/1/202517/6/2026
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AnalizadaMedia (6.3)0.19%—Oracle Communications Order AND Service Management21/1/202517/6/2026
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
AplazadaAlta (8.7)0.49%—Belledonne Communications Linphone-desktopAI17/1/202517/6/2026
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.
AplazadaAlta (7.1)0.16%—Ringcentral CommunicationsAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in pbmacintyre RingCentral Communications rccp-free allows Stored XSS.This issue affects RingCentral Communications: from n/a through <= 1.7.0.
AplazadaMedia (6.1)0.50%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAICisco Unified Communications Manager IM AND Presence ServiceAICisco Unity ConnectionAI18/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco&nbsp;Unified Communications Manager, Cisco&nbsp;Unified Communications Manager Session Management Edition, Cisco&nbsp;Unified Communications Manager IM &amp; Presence Service, and Cisco&nbsp;Unity Connection could allow an unauthenticated, remote attacker…