Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.78% | — | SAP Contact Center | 14/9/2021 | 17/6/2026 | Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing and to execute arbitrary code on the victim's browser. | |
| Modificada | Media (6.1) | 0.77% | — | SAP Contact Center | 14/9/2021 | 17/6/2026 | Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new email and to execute arbitrary code on the victim's browser. | |
| Modificada | Media (6.1) | 0.84% | — | SAP Contact Center | 14/9/2021 | 17/6/2026 | Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability when a user browses through the employee directory and to execute arbitrary code on the victim's… | |
| Modificada | Crítica (9.6) | 1.1% | — | SAP Contact Center | 14/9/2021 | 17/6/2026 | Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further… | |
| Modificada | Crítica (9.1) | 1.0% | — | Mitel Micontact Center Business | 13/8/2021 | 17/6/2026 | The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens. | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Unified Intelligence CenterCisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center Express | 16/6/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Media (6.1) | 0.82% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 8/4/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Mitel Micontact Center Enterprise | 29/3/2021 | 17/6/2026 | The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal. | |
| Modificada | Baja (3.3) | 0.27% | — | Mitel Micontact Center Business | 18/12/2020 | 17/6/2026 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization. | |
| Modificada | Alta (7.1) | 0.42% | — | Mitel Micontact Center Business | 25/9/2020 | 17/6/2026 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session. | |
| Modificada | Alta (7.2) | 3.4% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 23/9/2020 | 17/6/2026 | A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials.… | |
| Modificada | Alta (7.1) | 0.81% | — | Cisco Unified Contact Center Express | 3/6/2020 | 17/6/2026 | A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability… | |
| Modificada | Crítica (9.8) | 7.1% | — | Cisco Unified Contact Center Express | 22/5/2020 | 17/6/2026 | A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An… | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco Unified Communications ManagerCisco Unified Contact Center Express | 15/4/2020 | 17/6/2026 | A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability… | |
| Modificada | Media (6.5) | 0.92% | — | Mitel Micontact Center Business | 25/2/2020 | 17/6/2026 | The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow unauthorized access to user conversations. | |
| Modificada | Media (5.9) | 0.90% | — | Cisco Unified Contact Center Enterprise | 19/2/2020 | 17/6/2026 | A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly manages resources when processing inbound Live Data… | |
| Modificada | Media (6.1) | 0.90% | — | Cisco FinesseCisco Unified Contact Center Express | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Contact Center Express | 2/10/2019 | 17/6/2026 | A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Unified Contact Center Express | 5/9/2019 | 17/6/2026 | A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An… | |
| Modificada | Media (4.8) | 0.80% | — | Cisco Unified Contact Center Express | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to… | |
| Modificada | Crítica (9.8) | 1.6% | — | Enghouse Contact Center\ | 14/5/2019 | 17/6/2026 | ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka… | |
| Modificada | Alta (8.8) | 1.2% | — | Avaya IP Office Contact Center | 4/4/2019 | 17/6/2026 | A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior to 10.1.2.2.2-11201.1908. Unsupported… | |
| Modificada | Alta (8.8) | 0.57% | — | Cisco Packaged Contact Center Enterprise | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management… | |
| Modificada | Media (6.1) | 0.42% | — | Cisco Packaged Contact Center Enterprise | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a stored XSS attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040. |