Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 87% | ⚠ Explotación activa💥 Exploit | Mitel MicollabMitel Mivoice Business Express | 10/3/2022 | 17/6/2026 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for… | |
| Modificada | Alta (8.1) | 0.52% | — | Mitel Mivoice 6940 FirmwareMitel Mivoice 6930 Firmware | 18/12/2020 | 17/6/2026 | The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to… | |
| Analizada | Alta (8.8) | 3.1% | — | Mitel Mivoice Connect Client | 26/8/2020 | 17/6/2026 | A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allow an attacker to steal session cookies, perform directory traversal,… | |
| Modificada | Media (6.1) | 0.77% | — | Mitel Mivoice ConnectMitel Shoretel Conference WEB | 7/5/2020 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php. | |
| Analizada | Crítica (9.8) | 0.56% | — | Mitel Mivoice Connect Client | 17/4/2020 | 17/6/2026 | A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user credentials. | |
| Analizada | Crítica (9.8) | 3.0% | — | Mitel Mivoice Connect | 17/4/2020 | 17/6/2026 | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information. | |
| Modificada | Media (5.3) | 1.4% | — | Mitel MicollabMitel Mivoice Business Express | 12/11/2019 | 17/6/2026 | A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1 (8.0.2.202), could allow creation of unauthorized… | |
| Modificada | Media (6.1) | 1.1% | — | Mitel Mivoice Office 400 | 23/10/2018 | 17/6/2026 | A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to… | |
| Modificada | Crítica (9.8) | 4.9% | — | Mitel Mivoice 5330e Firmware | 23/10/2018 | 17/6/2026 | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Modificada | Media (6.5) | 1.1% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the signin… | |
| Modificada | Media (6.1) | 1.0% | — | Mitel Mivoice ConnectMitel ST 14.2 | 25/4/2018 | 17/6/2026 | A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | OpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+24 | 7/4/2014 | 17/6/2026 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to… |