Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.42% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend. | |
| Aplazada | Alta (8.6) | 0.65% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware. | |
| Aplazada | Media (6.5) | 0.43% | — | Starnet Communications Corporation FastxAI | 14/10/2025 | 17/6/2026 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files. | |
| Aplazada | Alta (7.2) | 0.24% | — | SSH Communications Security SSH Tectia ServerAI | 2/10/2025 | 17/6/2026 | SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic. | |
| Aplazada | Media (4.8) | 0.22% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI | 1/10/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Aplazada | Crítica (9.8) | 2.2% | 💥 Exploit | Siklu Communications Etherhaul 8010txAISiklu Communications Etherhaul 1200fxAI | 15/9/2025 | 5/7/2026 | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys hardcoded in the binary. These keys are identical across all devices, allowing… | |
| Analizada | Alta (8.8) | 0.18% | — | Cisco Unified Communications Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This… | |
| Analizada | Media (6.1) | 0.25% | — | Cisco Unified Communications Manager IM AND Presence Service | 3/9/2025 | 1/10/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based… | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Ringcentral CommunicationsAI | 28/8/2025 | 17/6/2026 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes. | |
| Aplazada | Alta (8.7) | 1.1% | — | Spon Communications IP Network Broadcast SystemAI | 27/8/2025 | 17/6/2026 | SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory… | |
| Analizada | Crítica (10) | 1.2% | — | Cisco Unified Communications Manager | 2/7/2025 | 17/6/2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed… | |
| Analizada | Media (6.7) | 0.18% | — | Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+4 | 4/6/2025 | 17/6/2026 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An… | |
| Aplazada | Media (5.1) | 0.14% | — | Cisco Unified Communications AND Contact Center SolutionsAI | 21/5/2025 | 17/6/2026 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit… | |
| Analizada | Media (5.5) | 0.20% | — | Oracle Communications Order AND Service Management | 15/4/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.8) | 0.14% | — | IBM Personal Communications | 8/4/2025 | 17/6/2026 | IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Carrcommunications RsvpmakerAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Carrcommunications RsvpmakerAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5. | |
| Analizada | Media (5.3) | 0.38% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (5.4) | 0.26% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (6.3) | 0.19% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.7) | 0.49% | — | Belledonne Communications Linphone-desktopAI | 17/1/2025 | 17/6/2026 | Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition. | |
| Aplazada | Alta (7.1) | 0.16% | — | Ringcentral CommunicationsAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pbmacintyre RingCentral Communications rccp-free allows Stored XSS.This issue affects RingCentral Communications: from n/a through <= 1.7.0. | |
| Aplazada | Media (6.1) | 0.50% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAICisco Unified Communications Manager IM AND Presence ServiceAICisco Unity ConnectionAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker… |