Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 33% | 💥 PoC | Microsoft Expression BlendMicrosoft Visual StudioMicrosoft Visual Studio 2017 | 11/7/2018 | 17/6/2026 | A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4. | |
| Modificada | Alta (8.8) | 1.9% | — | Expresscart Project Expresscart | 15/6/2018 | 17/6/2026 | expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header. | |
| Modificada | Alta (8.8) | 27% | — | Express-cart Project Express-cart | 7/6/2018 | 17/6/2026 | Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+9 | 7/6/2018 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain… | |
| Modificada | Alta (7.5) | 1.2% | — | Expressjs Method-override | 7/6/2018 | 17/6/2026 | method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the… | |
| Modificada | Alta (8.8) | 1.4% | — | Express-restify-mongoose Project Express-restify-mongoose | 31/5/2018 | 17/6/2026 | express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the… | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco Mobility Express Software | 2/5/2018 | 17/6/2026 | A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Application Express | 18/1/2018 | 17/6/2026 | Vulnerability in the Application Express component of Oracle Database Server. The supported version that is affected is Prior to 5.1.4.00.08. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express. Successful attacks require human interaction… | |
| Modificada | Media (5.4) | 0.51% | — | Expressionengine | 17/11/2017 | 17/6/2026 | EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection | |
| Modificada | Crítica (9.8) | 6.4% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+7 | 16/11/2017 | 17/6/2026 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration… | |
| Modificada | Alta (7.8) | 0.32% | — | Cisco Identity Services EngineCisco Identity Services Engine ExpressCisco Identity Services Engine Virtual Appliance | 2/11/2017 | 17/6/2026 | A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the… | |
| Modificada | Media (6.1) | 1.2% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | |
| Modificada | Media (6.1) | 1.3% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) | |
| Modificada | Crítica (9.8) | 1.8% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. | |
| Modificada | Media (4.3) | 1.6% | — | Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server | 19/10/2017 | 17/6/2026 | A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial… | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version. | |
| Modificada | Alta (8.1) | 0.98% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information. | |
| Modificada | Media (6.5) | 0.83% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function. | |
| Modificada | Media (6.5) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files. | |
| Modificada | Media (6.1) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system. | |
| Modificada | Media (6.1) | 1.1% | — | Openjsf Express | 9/8/2017 | 17/6/2026 | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center Express | 4/7/2017 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:… | |
| Modificada | Alta (7.5) | 4.0% | — | Expressionengine | 22/6/2017 | 17/6/2026 | ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. | |
| Modificada | Alta (7.5) | 0.73% | — | Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer | 20/6/2017 | 17/6/2026 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text… |