Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Teradata ExpressTeradata Gateway | 23/5/2017 | 17/6/2026 | Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database crash) via a malformed CONFIG REQUEST message. | |
| Modificada | Media (6.1) | 23% | — | Jqueryui Jquery UIOracle Application ExpressOracle Business IntelligenceOracle Hospitality Cruise Fleet Management+9 | 15/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. | |
| Modificada | Alta (8.6) | 3.5% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 1/2/2017 | 17/6/2026 | A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 2.0% | — | Cisco Expressway | 14/12/2016 | 17/6/2026 | A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This vulnerability affects Cisco Expressway Series Software and… | |
| Modificada | Alta (7.8) | 0.58% | — | Teradata Studio Express | 10/11/2016 | 17/6/2026 | The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges. | |
| Modificada | Alta (8.8) | 0.63% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 5/10/2016 | 17/6/2026 | The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653. | |
| Modificada | Media (5.8) | 3.2% | — | Oracle Application Express | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect availability via unknown vectors. | |
| Modificada | Media (6.1) | 1.7% | — | Oracle Application Express | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0.4 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (6.5) | 1.8% | — | HP Enterprise Security ManagerHP Enterprise Security Manager Express | 17/3/2016 | 17/6/2026 | HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.8% | — | NEC Expresscluster X | 30/1/2016 | 17/6/2026 | Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Contact Center Express | 26/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033. | |
| Modificada | Alta (7.5) | 3.5% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a related issue to CVE-2015-8384 and CVE-2015-8392. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pcre Perl Compatible Regular Expression LibraryPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client. | |
| Modificada | Alta (7.5) | 3.6% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion and buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror, a… | |
| Modificada | Crítica (9.8) | 4.7% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Alta (7.5) | 6.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Alta (7.3) | 3.6% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | |
| Modificada | Crítica (9.8) | 6.9% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraOracle LinuxPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by… | |
| Modificada | Alta (7.5) | 5.6% | — | Oracle LinuxPcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object… | |
| Modificada | Alta (7.5) | 3.4% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp… | |
| Modificada | Crítica (9.8) | 6.1% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject FedoraPHP | 2/12/2015 | 17/6/2026 | PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. |