Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | |
| Modificada | Media (6.1) | 1.3% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS) | |
| Modificada | Crítica (9.8) | 1.8% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 31/10/2017 | 17/6/2026 | An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. | |
| Modificada | Media (4.3) | 1.6% | — | Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server | 19/10/2017 | 17/6/2026 | A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial… | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features. | |
| Modificada | Media (5.3) | 1.5% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version. | |
| Modificada | Alta (8.1) | 0.98% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information. | |
| Modificada | Media (6.5) | 0.83% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function. | |
| Modificada | Media (6.5) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files. | |
| Modificada | Media (6.1) | 0.96% | — | HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express | 30/9/2017 | 17/6/2026 | A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system. | |
| Modificada | Media (6.1) | 1.1% | — | Openjsf Express | 9/8/2017 | 17/6/2026 | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center Express | 4/7/2017 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:… | |
| Modificada | Alta (7.5) | 4.0% | — | Expressionengine | 22/6/2017 | 17/6/2026 | ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution. | |
| Modificada | Alta (7.5) | 0.73% | — | Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer | 20/6/2017 | 17/6/2026 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text… | |
| Modificada | Alta (7.5) | 2.3% | — | Teradata ExpressTeradata Gateway | 23/5/2017 | 17/6/2026 | Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database crash) via a malformed CONFIG REQUEST message. | |
| Modificada | Media (6.1) | 23% | — | Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+9 | 15/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. | |
| Modificada | Alta (8.6) | 3.5% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 1/2/2017 | 17/6/2026 | A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 2.0% | — | Cisco Expressway | 14/12/2016 | 17/6/2026 | A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This vulnerability affects Cisco Expressway Series Software and… | |
| Modificada | Alta (7.8) | 0.58% | — | Teradata Studio Express | 10/11/2016 | 17/6/2026 | The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges. | |
| Modificada | Alta (8.8) | 0.63% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 5/10/2016 | 17/6/2026 | The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653. | |
| Modificada | Media (5.8) | 3.2% | — | Oracle Application Express | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect availability via unknown vectors. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Application Express | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (6.5) | 1.8% | — | HP Enterprise Security ManagerHP Enterprise Security Manager Express | 17/3/2016 | 17/6/2026 | HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. |