Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 4.0% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ pattern and related patterns involving (*ACCEPT), which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (partially… | |
| Modificada | Alta (7.5) | 5.3% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group… | |
| Modificada | Alta (7.5) | 4.4% | — | Pcre Perl Compatible Regular Expression LibraryFedoraproject Fedora | 2/12/2015 | 17/6/2026 | The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object… | |
| Modificada | Alta (7.5) | 4.0% | — | Pcre Perl Compatible Regular Expression Library | 2/12/2015 | 17/6/2026 | PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a… | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Alta (7.2) | 0.92% | 💥 Exploit | Vboxcomm Satellite Express Protocol | 21/9/2015 | 17/6/2026 | The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call. | |
| Modificada | Media (6.4) | 1.9% | — | Devexpress Ajax Control Toolkit | 18/8/2015 | 17/6/2026 | Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd. | |
| Modificada | Media (5) | 2.8% | — | Hotspotexpress Hotex Billing Manager | 16/4/2015 | 17/6/2026 | Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (4.3) | 1.9% | — | Hotspot Express Hotex Billing Manager | 14/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/hotspotlogin.cgi in Hotspot Express hotEx Billing Manager 73 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. | |
| Modificada | Alta (10) | 4.3% | — | Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software | 13/3/2015 | 17/6/2026 | The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Expressway SoftwareCisco Telepresence ConductorCisco Telepresence Video Communication Server Software | 13/3/2015 | 17/6/2026 | The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka… | |
| Modificada | Baja (2.1) | 0.31% | — | IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer | 17/1/2015 | 17/6/2026 | IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Media (6.5) | 1.6% | — | Ellislab ExpressionengineExpressionengine | 4/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php. | |
| Modificada | Alta (7.1) | 2.3% | — | Cisco Telepresence Video Communication Server SoftwareCisco Expressway Software | 19/10/2014 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447. | |
| Modificada | Alta (7.1) | 2.4% | — | Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software | 19/10/2014 | 17/6/2026 | The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252. | |
| Modificada | Alta (7.8) | 3.9% | — | Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software | 19/10/2014 | 17/6/2026 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507. | |
| Modificada | Media (5.4) | 0.27% | — | Aeroexpress | 16/10/2014 | 17/6/2026 | The Aeroexpress (aka ru.lynx.aero) application 2.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Express | 11/10/2014 | 17/6/2026 | The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | American Express Serve | 2/10/2014 | 17/6/2026 | The American Express Serve (aka com.serve.mobile) application @7F0901E4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.9) | 0.38% | — | Blackberry Enterprise ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express | 18/8/2014 | 17/6/2026 | BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file. | |
| Modificada | Media (4.3) | 1.4% | — | Nice Recording Express | 18/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3)… | |
| Modificada | Alta (7.5) | 1.9% | — | Nice Recording Express | 18/6/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 8.9% | 💥 Exploit | Devexpress Aspxfilemanager Control FOR Webforms AND MVC | 6/6/2014 | 17/6/2026 | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter. | |
| Modificada | Alta (10) | 4.2% | — | Juniper Network AND Security Manager SoftwareJuniper Nsm3000Juniper Nsmexpress | 19/5/2014 | 17/6/2026 | Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4) | 0.76% | — | Cisco Unified Contact Center EnterpriseCisco Unified Contact Center Express Editor Software | 29/4/2014 | 17/6/2026 | The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133. |