Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1092 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.42%—Cisco Unified Communications Manager18/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AnalizadaMedia (6.1)0.32%—Cisco Unified Communications Manager6/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AnalizadaMedia (6.5)0.44%—Cisco Unified Communications Manager IM AND Presence Service6/11/202417/6/2026
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of unencrypted credentials in…
ModificadaCrítica (9.8)0.51%—Carrcommunications Rsvpmaker4/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4.
AplazadaMedia (6.5)0.26%—Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI24/10/202417/6/2026
Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.
AplazadaAlta (8.8)1.7%—Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI24/10/202417/6/2026
Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.
AnalizadaMedia (5.4)0.42%—Millbeckcommunications Proroute H685t-w Firmware17/9/202417/6/2026
This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser session.
AnalizadaMedia (6.1)0.37%—Cisco Unified Communications Manager21/8/202417/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AnalizadaAlta (7.5)0.74%—Cisco Unified Communications Manager21/8/202417/6/2026
A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…
AplazadaAlta (8.8)0.79%💥 PoCShibang Communications IP Network Intercom Broadcasting SystemAI17/4/202417/6/2026
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
AnalizadaCrítica (10)0.79%—IBM Personal Communications6/4/202417/6/2026
IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT…
AnalizadaMedia (6.1)0.50%—Cisco Unified Communications Manager IM AND Presence Service3/4/202417/6/2026
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface. This vulnerability exists because the web-based…
AplazadaMedia (5.4)0.65%—Shibang Communications IP Network Intercom Broadcasting SystemAI3/4/202417/6/2026
A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible…
AplazadaMedia (6.1)0.42%—Inforest Communications SupercaliAI5/3/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page.
ModificadaCrítica (10)2.4%—Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity ConnectionCisco Unified Contact Center Express+126/1/202417/6/2026
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could…
ModificadaCrítica (9.8)0.85%—Carrcommunications Rsvpmaker29/12/202317/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6.
ModificadaCrítica (9.8)1.0%💥 PoCCarrcommunications Rsvpmaker3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.
ModificadaAlta (7.2)0.68%—Carrcommunications Rsvpmaker31/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.
ModificadaAlta (7.2)0.55%—Carrcommunications Rsvpmaker31/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.
ModificadaMedia (4.3)0.40%—Oracle Communications Order AND Service Management17/10/202317/6/2026
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: User Management). Supported versions that are affected are 7.4.0 and 7.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.5)0.81%—Cisco Emergency ResponderCisco Prime Collaboration DeploymentCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+14/10/202317/6/2026
A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is…
ModificadaMedia (4.8)0.37%—Carrcommunications Rsvpmaker27/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
ModificadaMedia (6.1)0.39%—Carrcommunications Rsvpmaker27/9/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
ModificadaAlta (7.8)0.19%—IBM Person Communications20/9/202317/6/2026
IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138.
ModificadaAlta (7.2)0.49%—Cisco Emergency ResponderCisco Unified Communications ManagerCisco Unity Connection30/8/202317/6/2026
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This…