Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.1%—Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+14/6/202117/6/2026
A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced…
ModificadaBaja (3.3)0.66%—Cisco Webex Network Recording PlayerCisco Webex Player3/6/202017/6/2026
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain…
ModificadaBaja (3.3)1.4%—Cisco Webex PlayerCisco Webex Network Recording Player3/6/202017/6/2026
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain…
ModificadaBaja (3.3)0.66%—Cisco Webex Network Recording PlayerCisco Webex Player3/6/202017/6/2026
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain…
ModificadaAlta (7.8)2.0%—Cisco Webex Network Recording PlayerCisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server15/4/202017/6/2026
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the…
ModificadaAlta (7.8)1.9%—Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player4/3/202017/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored…
ModificadaAlta (7.8)2.4%—Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player4/3/202017/6/2026
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored…
ModificadaCrítica (9.8)7.9%💥 ExploitNapc Xinet Elegant 6 Asset Library2/12/201917/6/2026
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
ModificadaCrítica (9.6)3.8%—Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player4/1/201817/6/2026
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and…
ModificadaAlta (7.8)1.7%—Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player4/1/201817/6/2026
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and…
ModificadaAlta (7.8)1.2%—Gstn India Goods AND Services TAX Network Offline Utility Tool14/9/201717/6/2026
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example,…
ModificadaAlta (7.6)6.4%—XinetdRedhat Enterprise Linux10/10/201316/6/2026
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
ModificadaAlta (7.5)2.5%—Intel Wimax Network Service25/8/201316/6/2026
Multiple integer overflows in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices allow remote attackers to cause a denial of service (component crash) or possibly execute arbitrary code via an L5 connection with a crafted PDU value that triggers a heap-based buffer overflow…
ModificadaBaja (2.1)0.31%—Intel Wimax Network Service25/8/201316/6/2026
The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicant_key.pem on all systems, which allows local users to obtain sensitive…
ModificadaBaja (2.1)0.36%—Intel Wimax Network Service25/8/201316/6/2026
The OSAL_Crypt_SetEncryptedPassword function in InfraStack/OSDependent/Linux/OSAL/Services/wimax_osal_crypt_services.c in the OSAL crypt module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices logs a cleartext password during certain attempts to set a password, which…
ModificadaBaja (2.1)0.33%—Intel Wimax Network Service25/8/201316/6/2026
The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses world-writable permissions for wimaxd.log, which allows local users to cause a denial of…
ModificadaMedia (4.3)2.8%—Xinetd4/6/201216/6/2026
builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.
ModificadaMedia (4.3)1.4%💥 ExploitPhoetux.net Phxcontacts30/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.
ModificadaAlta (7.5)1.1%💥 ExploitPhoetux.net Phxcontacts30/3/200616/6/2026
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.
ModificadaMedia (6.2)0.36%—Linux NetkitLinux-vserverLinux Kernel7/3/200516/6/2026
Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.
ModificadaAlta (10)4.5%—Linux NetkitSsltelnetd Secure Telnet6/8/200416/6/2026
Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.
ModificadaMedia (5)8.9%💥 ExploitXinetd5/5/200316/6/2026
Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.
ModificadaBaja (2.1)0.37%—Xinetd5/9/200216/6/2026
xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.
ModificadaBaja (2.1)0.34%—Xinet K-ashareSGI Irix16/5/200216/6/2026
xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
ModificadaAlta (10)3.6%—Xinetd6/12/200116/6/2026
Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.