Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)33%💥 PoCMicrosoft Expression BlendMicrosoft Visual StudioMicrosoft Visual Studio 201711/7/201817/6/2026
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
ModificadaAlta (8.8)1.9%—Expresscart Project Expresscart15/6/201817/6/2026
expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
ModificadaAlta (8.8)27%—Express-cart Project Express-cart7/6/201817/6/2026
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
ModificadaAlta (7.5)2.0%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+97/6/201817/6/2026
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain…
ModificadaAlta (7.5)1.2%—Expressjs Method-override7/6/201817/6/2026
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the…
ModificadaAlta (8.8)1.4%—Express-restify-mongoose Project Express-restify-mongoose31/5/201817/6/2026
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the…
ModificadaAlta (7.5)2.2%—Cisco Mobility Express Software2/5/201817/6/2026
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The…
ModificadaMedia (6.1)1.1%—Oracle Application Express18/1/201817/6/2026
Vulnerability in the Application Express component of Oracle Database Server. The supported version that is affected is Prior to 5.1.4.00.08. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express. Successful attacks require human interaction…
ModificadaMedia (5.4)0.51%—Expressionengine17/11/201717/6/2026
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
ModificadaCrítica (9.8)6.4%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+716/11/201717/6/2026
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration…
ModificadaAlta (7.8)0.32%—Cisco Identity Services EngineCisco Identity Services Engine ExpressCisco Identity Services Engine Virtual Appliance2/11/201717/6/2026
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the…
ModificadaMedia (6.1)1.2%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
ModificadaMedia (6.1)1.3%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)
ModificadaCrítica (9.8)1.8%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
ModificadaMedia (4.3)1.6%—Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server19/10/201717/6/2026
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial…
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
ModificadaAlta (8.1)0.98%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.
ModificadaMedia (6.5)0.83%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.
ModificadaMedia (6.5)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
ModificadaMedia (6.1)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.
ModificadaMedia (6.1)1.1%—Openjsf Express9/8/201717/6/2026
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center Express4/7/201717/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:…
ModificadaAlta (7.5)4.0%—Expressionengine22/6/201717/6/2026
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
ModificadaAlta (7.5)0.73%—Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer20/6/201717/6/2026
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text…
Orbitaley — Vulnerabilidades