Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.0% | — | Cisco Telepresence Video Communication Server | 18/4/2019 | 17/6/2026 | A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to… | |
| Modificada | Media (4.9) | 1.7% | — | Cisco Telepresence Video Communication Server | 18/4/2019 | 17/6/2026 | A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to improper… | |
| Modificada | Media (5) | 2.1% | — | Cisco Telepresence Video Communication ServerCisco Telepresence Conductor | 7/2/2019 | 17/6/2026 | A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred… | |
| Modificada | Alta (7.2) | 2.9% | — | Cisco Telepresence Video Communication Server | 5/10/2018 | 17/6/2026 | A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the… | |
| Modificada | Alta (7.5) | 3.5% | — | Cisco Telepresence Video Communication ServerCisco Unified Communications Manager IM AND Presence Service | 15/8/2018 | 17/6/2026 | A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a… | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Telepresence Video Communication Server | 21/6/2018 | 17/6/2026 | A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file descriptors while processing a high volume of traffic. An… | |
| Modificada | Media (4.3) | 1.6% | — | Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server | 19/10/2017 | 17/6/2026 | A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial… | |
| Modificada | Media (6.8) | 2.0% | — | Cisco Telepresence Video Communication Server | 17/8/2017 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) on the Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the targeted appliance. The vulnerability is due to excessive SIP traffic sent to the device. An attacker… | |
| Modificada | Alta (8.6) | 3.5% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 1/2/2017 | 17/6/2026 | A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient… | |
| Modificada | Alta (8.8) | 2.9% | — | Cisco Telepresence Video Communication Server | 8/8/2016 | 17/6/2026 | The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531. | |
| Modificada | Media (6.5) | 1.2% | — | Cisco Telepresence Video Communication ServerCisco Telepresence Video Communication Server Software | 7/7/2016 | 17/6/2026 | The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601. | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Telepresence Video Communication Server | 25/5/2016 | 17/6/2026 | Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258. | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Telepresence Video Communication Server Software | 12/3/2016 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026. | |
| Modificada | Media (5.3) | 1.5% | — | Cisco Telepresence Video Communication Server Software | 9/2/2016 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362. | |
| Modificada | Media (4) | 1.7% | — | Cisco Telepresence Video Communication Server Software | 14/12/2015 | 17/6/2026 | The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setup restrictions by spoofing a user, aka Bug ID CSCuu97283. | |
| Modificada | Baja (2.1) | 0.23% | — | Cisco Telepresence Video Communication Server Software | 13/12/2015 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516. | |
| Modificada | Media (4) | 1.7% | — | Cisco Telepresence Video Communication Server Software | 13/12/2015 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651. | |
| Modificada | Media (6.8) | 0.59% | — | Cisco Telepresence Video Communication Server Software | 21/11/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412. | |
| Modificada | Media (6.9) | 0.36% | — | Cisco Telepresence Video Communication Server Software | 12/10/2015 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969. | |
| Modificada | Media (6.9) | 0.39% | — | Cisco Telepresence Video Communication Server Software | 12/10/2015 | 17/6/2026 | The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering the restart of a process by the root account, aka Bug ID CSCuv12272. | |
| Modificada | Media (6.9) | 0.54% | — | Cisco Telepresence Video Communication Server Software | 2/9/2015 | 17/6/2026 | A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556. | |
| Modificada | Media (4) | 1.5% | — | Cisco Telepresence Video Communication Server Software | 26/8/2015 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531. | |
| Modificada | Media (5) | 2.4% | — | Cisco Telepresence Video Communication Server Software | 20/8/2015 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote attackers to cause a denial of service via invalid variables in a GET request, aka Bug ID CSCuv40528. | |
| Modificada | Media (6.5) | 2.3% | — | Cisco Telepresence Video Communication Server Software | 20/8/2015 | 17/6/2026 | The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796. |