Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)4.0%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially…
ModificadaAlta (7.5)5.3%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group…
ModificadaAlta (7.5)4.4%—Pcre Perl Compatible Regular Expression LibraryFedoraproject Fedora2/12/201517/6/2026
The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object…
ModificadaAlta (7.5)4.0%—Pcre Perl Compatible Regular Expression Library2/12/201517/6/2026
PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a…
ModificadaAlta (7.2)0.61%—HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+34/11/201517/6/2026
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
ModificadaAlta (7.2)0.92%💥 ExploitVboxcomm Satellite Express Protocol21/9/201517/6/2026
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.
ModificadaMedia (6.4)1.9%—Devexpress Ajax Control Toolkit18/8/201517/6/2026
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.
ModificadaMedia (5)2.8%—Hotspotexpress Hotex Billing Manager16/4/201517/6/2026
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
ModificadaMedia (4.3)1.9%—Hotspot Express Hotex Billing Manager14/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
ModificadaAlta (10)4.3%—Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software13/3/201517/6/2026
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs…
ModificadaAlta (7.8)1.9%—Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software13/3/201517/6/2026
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka…
ModificadaBaja (2.1)0.31%—IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer17/1/201517/6/2026
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
ModificadaMedia (6.5)1.6%—Ellislab ExpressionengineExpressionengine4/11/201417/6/2026
Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
ModificadaAlta (7.1)2.3%—Cisco Telepresence Video Communication Server SoftwareCisco Expressway Software19/10/201417/6/2026
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
ModificadaAlta (7.1)2.4%—Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software19/10/201417/6/2026
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
ModificadaAlta (7.8)3.9%—Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software19/10/201417/6/2026
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507.
ModificadaMedia (5.4)0.27%—Aeroexpress16/10/201417/6/2026
The Aeroexpress (aka ru.lynx.aero) application 2.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Express11/10/201417/6/2026
The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—American Express Serve2/10/201417/6/2026
The American Express Serve (aka com.serve.mobile) application @7F0901E4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.9)0.38%—Blackberry Enterprise ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express18/8/201417/6/2026
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
ModificadaMedia (4.3)1.4%—Nice Recording Express18/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3)…
ModificadaAlta (7.5)1.9%—Nice Recording Express18/6/201417/6/2026
Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.5)8.9%💥 ExploitDevexpress Aspxfilemanager Control FOR Webforms AND MVC6/6/201417/6/2026
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
ModificadaAlta (10)4.2%—Juniper Network AND Security Manager SoftwareJuniper Nsm3000Juniper Nsmexpress19/5/201417/6/2026
Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4)0.76%—Cisco Unified Contact Center EnterpriseCisco Unified Contact Center Express Editor Software29/4/201417/6/2026
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.
Orbitaley — Vulnerabilidades