Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
ModificadaMedia (6.1)1.3%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow Reflected and Stored Cross-Site Scripting (XSS)
ModificadaCrítica (9.8)1.8%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express31/10/201717/6/2026
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
ModificadaMedia (4.3)1.6%—Cisco ExpresswayCisco Telepresence ConductorCisco Telepresence Video Communication Server19/10/201717/6/2026
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial…
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
ModificadaMedia (5.3)1.5%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
ModificadaAlta (8.1)0.98%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.
ModificadaMedia (6.5)0.83%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of storage groups and enable/disable the setting for the 'follow schedule' function.
ModificadaMedia (6.5)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
ModificadaMedia (6.1)0.96%—HP Arcsight Enterprise Security ManagerHP Arcsight Enterprise Security Manager Express30/9/201717/6/2026
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a specific URL is sent to the system.
ModificadaMedia (6.1)1.1%—Openjsf Express9/8/201717/6/2026
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center Express4/7/201717/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:…
ModificadaAlta (7.5)4.0%—Expressionengine22/6/201717/6/2026
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
ModificadaAlta (7.5)0.73%—Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer20/6/201717/6/2026
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text…
ModificadaAlta (7.5)2.3%—Teradata ExpressTeradata Gateway23/5/201717/6/2026
Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database crash) via a malformed CONFIG REQUEST message.
ModificadaMedia (6.1)23%—Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+915/3/201717/6/2026
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
ModificadaAlta (8.6)3.5%—Cisco ExpresswayCisco Telepresence Video Communication Server1/2/201717/6/2026
A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient…
ModificadaMedia (6.5)2.0%—Cisco Expressway14/12/201617/6/2026
A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This vulnerability affects Cisco Expressway Series Software and…
ModificadaAlta (7.8)0.58%—Teradata Studio Express10/11/201617/6/2026
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.
ModificadaAlta (8.8)0.63%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center6/10/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
ModificadaMedia (6.1)1.0%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center6/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
ModificadaAlta (7.5)1.3%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center5/10/201617/6/2026
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
ModificadaMedia (5.8)3.2%—Oracle Application Express21/7/201617/6/2026
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect availability via unknown vectors.
ModificadaMedia (6.1)1.7%—Oracle Application Express21/7/201617/6/2026
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect confidentiality and integrity via unknown vectors.
ModificadaMedia (6.5)1.8%—HP Enterprise Security ManagerHP Enterprise Security Manager Express17/3/201617/6/2026
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors.
Orbitaley — Vulnerabilidades