Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

8451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.39%—Tanium Discover26/1/202617/6/2026
Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
AnalizadaMedia (4.9)0.44%—Tanium Discover26/1/202617/6/2026
Tanium addressed an improper input validation vulnerability in Discover.
AplazadaAlta (7.3)0.39%💥 PoCDiscord ClientAI23/1/202617/6/2026
Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaAlta (7.1)0.26%—Expresstechsoftware Memberpress Discord AddonAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon expresstechsoftwares-memberpress-discord-add-on allows Reflected XSS.This issue affects MemberPress Discord Addon: from n/a through <= 1.1.4.
AplazadaMedia (4.3)0.29%💥 PoCDiscordAI22/1/202613/9/2026
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is…
AplazadaMedia (4.8)0.20%—Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI21/1/202617/6/2026
These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the…
AplazadaMedia (6)0.12%—Cisco Intersight Virtual ApplianceAI21/1/202617/6/2026
A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerability is due to improper file permissions on configuration files for system accounts…
AplazadaMedia (5.3)0.37%—Cisco Iec6400 Wireless Backhaul Edge Compute SoftwareAI21/1/202617/6/2026
A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause the SSH service to stop responding. This vulnerability exists because the SSH service lacks effective flood protection. An attacker could exploit this vulnerability by…
AplazadaMedia (4.8)0.20%—Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI21/1/202617/6/2026
These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the…
AnalizadaCrítica (9.8)4.5%⚠ Explotación activa💥 PoCCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection21/1/202617/6/2026
—
AplazadaAlta (7.5)9.2%—ISC BindAI21/1/20261/9/2026
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.
AplazadaAlta (8.5)0.17%—Acer Backup ManagerAINTI IschedulesvcAI16/1/202617/6/2026
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with…
AnalizadaMedia (4.8)0.39%—Stackideas Easydiscuss16/1/202617/6/2026
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
AnalizadaCrítica (9.4)0.20%—Stackideas Easydiscuss16/1/202617/6/2026
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
AnalizadaCrítica (9.4)0.20%—Stackideas Easydiscuss16/1/202617/6/2026
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
AnalizadaMedia (4.8)0.27%—Cisco Identity Services Engine15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based…
AnalizadaMedia (4.8)0.26%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AnalizadaMedia (4.8)0.27%—Cisco Identity Services Engine15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient…
AplazadaMedia (4.9)6.2%—Cisco Identity Services EngineAICisco Identity Services Engine Passive Identity ConnectorAI7/1/202617/6/2026
This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the…
AplazadaMedia (5.3)0.60%—Cisco Snort 3AI7/1/202617/6/2026
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error…
AplazadaMedia (5.8)0.67%—Cisco Snort 3AI7/1/202617/6/2026
Multiple&nbsp;Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resulting in an interruption of packet inspection. This vulnerability is due to an…
AplazadaMedia (4.3)0.18%—Wpdiscover Accordion Slider GalleryAI31/12/202517/6/2026
Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7.
AplazadaMedia (5.4)0.12%—Iscripts EasyindexAI31/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n/a through <= 1.1.1704.
AnalizadaMedia (6.3)0.29%—Discourse30/12/202517/6/2026
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
AplazadaMedia (4.3)0.18%—Marketing Fire Wp-discussion-boardAI30/12/20257/10/2026
Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Discussion Board: from n/a through <= 2.5.7.