Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
261 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco… | |
| Modificada | Media (4.9) | 1.3% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Emergency ResponderCisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 13/1/2021 | 17/6/2026 | A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an… | |
| Modificada | Media (6.5) | 1.2% | — | Cisco Unified Communications Manager IM AND Presence Service | 6/11/2020 | 17/6/2026 | A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerability is due to… | |
| Modificada | Alta (8.8) | 0.54% | — | Cisco Unified Communications Manager | 23/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management… | |
| Modificada | Media (6.5) | 0.94% | — | Cisco Unified Communications Manager | 23/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the… | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Unified Communications Manager | 17/8/2020 | 17/6/2026 | A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 2/7/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a… | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco Unified Communications ManagerCisco Unified Contact Center Express | 15/4/2020 | 17/6/2026 | A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability… | |
| Modificada | Media (6.1) | 0.79% | — | Cisco Unified Communications Manager | 19/2/2020 | 17/6/2026 | A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this… | |
| Modificada | Alta (8.8) | 1.6% | 💥 PoC | Cisco Unified Communications Manager | 26/11/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could… | |
| Modificada | Media (6.5) | 0.67% | — | Cisco Unified Communications ManagerCisco Unity ConnectionCisco Unified Communications Manager IM AND Presence Service | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to… | |
| Modificada | Media (6.5) | 1.3% | — | Cisco Unified Communications Manager | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper handling of malformed HTTP methods. An… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Communications Manager | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Communications Manager | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software.… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Unified Communications Manager | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper… | |
| Modificada | Media (4.9) | 1.5% | — | Cisco Unified Communications Manager | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by executing arbitrary SQL queries. The vulnerability exists… | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of… | |
| Modificada | Alta (7.5) | 1.8% | — | Cisco Unified Communications Manager | 6/7/2019 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of input SIP traffic. An attacker could exploit this… | |
| Modificada | Alta (8.6) | 4.6% | — | Cisco Telepresence Video Communication ServerCisco Unified Communications Manager IM AND Presence Service | 5/6/2019 | 17/6/2026 | A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to… | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Unified Communications Manager | 18/4/2019 | 17/6/2026 | A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input parameters in the UDS API requests. An… | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Unified Communications Manager | 10/1/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An attacker could exploit this… | |
| Modificada | Media (5.4) | 1.2% | — | Cisco Unified Communications ManagerCisco Unity ConnectionCisco Unified Communications Manager IM AND Presence ServiceCisco Emergency Responder | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper… | |
| Modificada | Alta (7.5) | 3.5% | — | Cisco Telepresence Video Communication ServerCisco Unified Communications Manager IM AND Presence Service | 15/8/2018 | 17/6/2026 | A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco Unified Communications Manager | 1/8/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… |