Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.42% | — | Cisco Unified Communications Manager | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Unified Communications Manager | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Media (6.5) | 0.44% | — | Cisco Unified Communications Manager IM AND Presence Service | 6/11/2024 | 17/6/2026 | A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of unencrypted credentials in… | |
| Modificada | Crítica (9.8) | 0.51% | — | Carrcommunications Rsvpmaker | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication. | |
| Aplazada | Alta (8.8) | 1.7% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp. | |
| Analizada | Media (5.4) | 0.42% | — | Millbeckcommunications Proroute H685t-w Firmware | 17/9/2024 | 17/6/2026 | This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser session. | |
| Analizada | Media (6.1) | 0.37% | — | Cisco Unified Communications Manager | 21/8/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Alta (7.5) | 0.74% | — | Cisco Unified Communications Manager | 21/8/2024 | 17/6/2026 | A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Aplazada | Alta (8.8) | 0.79% | 💥 PoC | Shibang Communications IP Network Intercom Broadcasting SystemAI | 17/4/2024 | 17/6/2026 | File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component. | |
| Analizada | Crítica (10) | 0.79% | — | IBM Personal Communications | 6/4/2024 | 17/6/2026 | IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT… | |
| Analizada | Media (6.1) | 0.50% | — | Cisco Unified Communications Manager IM AND Presence Service | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface. This vulnerability exists because the web-based… | |
| Aplazada | Media (5.4) | 0.65% | — | Shibang Communications IP Network Intercom Broadcasting SystemAI | 3/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible… | |
| Aplazada | Media (6.1) | 0.42% | — | Inforest Communications SupercaliAI | 5/3/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page. | |
| Modificada | Crítica (10) | 2.4% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+1 | 26/1/2024 | 17/6/2026 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could… | |
| Modificada | Crítica (9.8) | 0.85% | — | Carrcommunications Rsvpmaker | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Carrcommunications Rsvpmaker | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6. | |
| Modificada | Alta (7.2) | 0.68% | — | Carrcommunications Rsvpmaker | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. | |
| Modificada | Alta (7.2) | 0.55% | — | Carrcommunications Rsvpmaker | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. | |
| Modificada | Media (4.3) | 0.40% | — | Oracle Communications Order AND Service Management | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: User Management). Supported versions that are affected are 7.4.0 and 7.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 0.81% | — | Cisco Emergency ResponderCisco Prime Collaboration DeploymentCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 4/10/2023 | 17/6/2026 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is… | |
| Modificada | Media (4.8) | 0.37% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | |
| Modificada | Alta (7.8) | 0.19% | — | IBM Person Communications | 20/9/2023 | 17/6/2026 | IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138. | |
| Modificada | Alta (7.2) | 0.49% | — | Cisco Emergency ResponderCisco Unified Communications ManagerCisco Unity Connection | 30/8/2023 | 17/6/2026 | A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This… |