Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.19%—Hornerautomation CscapeAI13/12/202417/6/2026
Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.
AplazadaAlta (7.1)0.27%—Copyscape PremiumAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Copyscape Copyscape Premium copyscape-premium allows Stored XSS.This issue affects Copyscape Premium: from n/a through <= 1.3.9.
ModificadaMedia (5.7)0.30%—SAP Landscape Management9/7/202417/6/2026
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.
AnalizadaAlta (8.8)0.45%—Mitel 6940w FirmwareMitel 6930w FirmwareMitel 6920w FirmwareMitel 6970 Firmware+108/4/202417/6/2026
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
AnalizadaCrítica (9.8)0.59%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
AnalizadaCrítica (9.8)0.64%—Dell Enterprise Storage Integrator FOR SAP Landscape Management15/2/202417/6/2026
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
AnalizadaMedia (4.3)0.45%—Unify Openscape Voice Trace Manager8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.
AnalizadaAlta (8.8)1.2%—Unify Openscape Voice Trace Manager8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.
AnalizadaMedia (6.1)0.33%—Unify Openscape Voice Trace Manager8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.
ModificadaCrítica (9.8)0.70%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
ModificadaAlta (8.8)0.92%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
ModificadaMedia (5.5)0.30%—Globalscape Cuteftp2/2/202417/6/2026
A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and…
ModificadaAlta (7.8)0.21%—Hornerautomation Cscape15/1/202417/6/2026
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
ModificadaAlta (7.5)1.0%—Unify Openscape Voice12/1/202417/6/2026
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying…
ModificadaAlta (8.8)0.26%—Arulprasadj Prevent Landscape Rotation18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.
ModificadaCrítica (9.8)1.9%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller5/12/202317/6/2026
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120.
ModificadaAlta (8.8)0.90%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.
ModificadaAlta (8.8)0.71%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of arbitrary files affecting the underlying…
ModificadaAlta (8.8)0.81%—Atos Unify Openscape Common Management9/10/202317/6/2026
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.
ModificadaAlta (8.8)0.57%—Atos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034.
ModificadaAlta (7.5)0.47%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as…
ModificadaAlta (7.2)32%—Redwood Jscape MFT7/9/202317/6/2026
Unsafe deserialization in JSCAPE MFT Server versions prior to 2023.1.9 (Windows, Linux, and MacOS) permits an attacker to run arbitrary Java code (including OS commands) via its management interface