Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.8% | — | Cisco Context Service Development KIT | 13/6/2017 | 17/6/2026 | A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server. More Information: CSCvb66730. Known Affected Releases: 2.0. | |
| Modificada | Media (6.1) | 0.76% | — | Netresearch Contexts Wurfl | 12/2/2017 | 17/6/2026 | An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker could execute arbitrary HTML and script… | |
| Modificada | Alta (8.6) | 2.7% | — | Cisco ASA CX Context-aware Security Software | 1/2/2017 | 17/6/2026 | A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is… | |
| Modificada | Alta (8.8) | 2.5% | — | Cisco Prime Security ManagerCisco ASA CX Context-aware Security Software | 7/2/2016 | 17/6/2026 | The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842. | |
| Modificada | Media (4) | 1.4% | — | Cisco ASA CX Context-aware Security Software | 30/10/2015 | 17/6/2026 | The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access restrictions and obtain sensitive user information via an unspecified HTTP request, aka Bug ID CSCuv74105. | |
| Modificada | Alta (7.8) | 2.3% | — | Cisco ASA With Firepower ServicesCisco ASA CX Context-aware Security Software | 11/4/2015 | 17/6/2026 | The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and… | |
| Modificada | Media (5.8) | 2.2% | — | Context Project ContextFedoraproject Fedora | 15/1/2015 | 17/6/2026 | Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Context Form Alteration Module | 6/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Ajaydsouza Contextual Related Posts | 2/6/2014 | 17/6/2026 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Ajaydsouza Contextual Related Posts | 2/6/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (4) | 2.0% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface data via crafted field values, aka Bug ID CSCuj45353. | |
| Modificada | Media (4.3) | 2.3% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cisco Context Directory Agent (CDA) allows remote attackers to modify the cache via a replay attack involving crafted RADIUS accounting messages, aka Bug ID CSCuj45383. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj45358. | |
| Modificada | Media (4.9) | 1.8% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements, which allows remote authenticated users to obtain administrative access by hijacking a session, aka Bug ID CSCuj45347. | |
| Modificada | Media (6.8) | 1.5% | — | Steven Jones Context | 7/12/2013 | 16/6/2026 | The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax… | |
| Modificada | Media (4.9) | 1.6% | — | Steven Jones Context | 7/12/2013 | 16/6/2026 | The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user… | |
| Modificada | Media (5) | 1.2% | — | Cisco Adaptive Security Appliance CX Context-aware Security Software | 4/11/2013 | 16/6/2026 | The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions via unspecified vectors, aka Bug ID CSCui94622. | |
| Modificada | Media (5.4) | 1.3% | — | Cisco ASA CX Context-aware Security Software | 18/6/2013 | 16/6/2026 | Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear to have been forwarded by a Cisco Adaptive Security Appliances (ASA) device, aka Bug ID CSCue88386. | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+7 | 29/4/2013 | 16/6/2026 | The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+6 | 19/2/2013 | 16/6/2026 | The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services… | |
| Modificada | Media (5) | 1.7% | — | Steven Jones Context | 3/1/2013 | 16/6/2026 | The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco ASA CX Context-aware SecurityCisco Prime Security Manager | 12/9/2012 | 16/6/2026 | The Cisco ASA-CX Context-Aware Security module before 9.0.2-103 for Adaptive Security Appliances (ASA) devices, and Prime Security Manager (aka PRSM) before 9.0.2-103, allows remote attackers to cause a denial of service (disk consumption and application hang) via unspecified IPv4 packets that trigger log entries, aka… | |
| Modificada | Baja (2.1) | 1.2% | — | Steven Jones Context | 19/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description. | |
| Modificada | Alta (9.3) | 36% | — | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Baja (2.1) | 0.43% | — | Context TexutilAI | 31/12/2004 | 16/6/2026 | TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log. |