Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.33%—Unify Openscape Voice Trace Manager8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.
ModificadaCrítica (9.8)0.70%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
ModificadaAlta (8.8)0.92%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
ModificadaMedia (5.9)1.2%—Opensc Project OpenscRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+731/1/202417/6/2026
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
ModificadaAlta (7.5)1.0%—Unify Openscape Voice12/1/202417/6/2026
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying…
ModificadaCrítica (9.8)1.9%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller5/12/202317/6/2026
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain…
ModificadaBaja (3.8)0.52%—Opensc Project OpenscFedoraproject FedoraRedhat Enterprise Linux6/11/202317/6/2026
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses…
ModificadaMedia (6.4)1.3%—Opensc Project OpenscRedhat Enterprise Linux6/11/202317/6/2026
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or…
ModificadaMedia (6.6)1.0%—Opensc Project OpenscRedhat Enterprise Linux6/11/202317/6/2026
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small,…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120.
ModificadaAlta (8.8)0.90%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.
ModificadaAlta (8.8)0.71%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of arbitrary files affecting the underlying…
ModificadaAlta (8.8)0.81%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.
ModificadaAlta (8.8)0.57%—Atos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034.
ModificadaAlta (7.5)0.47%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as…
ModificadaAlta (7.5)1.4%—Opensc Project Opensc22/8/202317/6/2026
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
ModificadaAlta (8.8)1.6%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager12/6/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557.
ModificadaCrítica (9.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager12/6/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.
ModificadaAlta (8.8)1.6%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager12/6/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556.
ModificadaAlta (8.8)1.6%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager12/6/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554.
ModificadaAlta (8.8)1.6%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager12/6/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036.
ModificadaAlta (7.1)0.29%—Opensc Project OpenscRedhat Enterprise Linux1/6/202317/6/2026
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly…
ModificadaAlta (7.2)0.96%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller14/4/202317/6/2026
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.