Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.31%—IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer17/1/201517/6/2026
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
ModificadaMedia (6.5)1.6%—Ellislab ExpressionengineExpressionengine4/11/201417/6/2026
Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
ModificadaAlta (7.1)2.3%—Cisco Telepresence Video Communication Server SoftwareCisco Expressway Software19/10/201417/6/2026
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
ModificadaAlta (7.1)2.4%—Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software19/10/201417/6/2026
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
ModificadaAlta (7.8)3.9%—Cisco Expressway SoftwareCisco Telepresence Video Communication Server Software19/10/201417/6/2026
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507.
ModificadaMedia (5.4)0.27%—Aeroexpress16/10/201417/6/2026
The Aeroexpress (aka ru.lynx.aero) application 2.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Express11/10/201417/6/2026
The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—American Express Serve2/10/201417/6/2026
The American Express Serve (aka com.serve.mobile) application @7F0901E4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.9)0.38%—Blackberry Enterprise ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express18/8/201417/6/2026
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
ModificadaMedia (4.3)1.4%—Nice Recording Express18/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3)…
ModificadaAlta (7.5)1.9%—Nice Recording Express18/6/201417/6/2026
Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.5)8.9%💥 ExploitDevexpress Aspxfilemanager Control FOR Webforms AND MVC6/6/201417/6/2026
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
ModificadaAlta (10)4.2%—Juniper Network AND Security Manager SoftwareJuniper Nsm3000Juniper Nsmexpress19/5/201417/6/2026
Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4)0.76%—Cisco Unified Contact Center EnterpriseCisco Unified Contact Center Express Editor Software29/4/201417/6/2026
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.
ModificadaAlta (9.3)5.2%—Autodesk SketchbookAutodesk Sketchbook ExpressAutodesk Sketchbook FOR Enterprise 2014Autodesk Sketchbook PRO2/4/201416/6/2026
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.
ModificadaMedia (5)1.2%—IBM Cognos Express25/3/201416/6/2026
IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.
ModificadaMedia (5)1.7%—IBM Cognos Express25/3/201416/6/2026
The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.
ModificadaMedia (6.8)0.82%—IBM Cognos Express25/3/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)2.4%—Intel Expressway Cloud Access 360Mcafee Cloud Identity ManagerMcafee Cloud Single Sign ON18/3/201417/6/2026
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown…
ModificadaMedia (4)1.4%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575.
ModificadaMedia (4)1.3%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCum95536.
ModificadaMedia (6.8)0.82%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502.
ModificadaMedia (5)1.3%—Blackberry Enterprise ServiceBlackberry Universal Device ServiceBlackberry Enterprise ServerBlackberry Enterprise Server Express14/2/201417/6/2026
BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise…
ModificadaMedia (6.9)0.36%—Intel C202 ChipsetIntel C204 ChipsetIntel C206 ChipsetIntel C216 Chipset+612/9/201316/6/2026
Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked,…
ModificadaMedia (4.3)1.6%💥 ExploitBMC Service Desk Express29/7/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.