Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Cisco Telepresence System SoftwareCisco Telepresence Video Communication Server | 1/3/2012 | 16/6/2026 | Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Telepresence System SoftwareCisco Telepresence Video Communication Server | 1/3/2012 | 16/6/2026 | Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426. | |
| Modificada | Media (4.3) | 1.7% | — | Cisco Telepresence Video Communication ServersCisco Telepresence Video Communication Servers Software | 19/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, aka Bug ID CSCts80342. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Alta (10) | 3.3% | — | Vsecurity Tandberg Video Communication Server | 13/4/2010 | 16/6/2026 | Unspecified vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to execute arbitrary code via unknown vectors, aka Reference ID 69773. | |
| Modificada | Media (4.3) | 0.85% | — | Vsecurity Tandberg Video Communication Server | 13/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Reference ID 66316. | |
| Modificada | Media (4) | 5.5% | — | Vsecurity Tandberg Video Communication Server | 13/4/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php. | |
| Modificada | Alta (8.5) | 2.1% | — | Vsecurity Tandberg Video Communication Server | 13/4/2010 | 16/6/2026 | The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to conduct man-in-the-middle attacks and spoof arbitrary servers via crafted SSH packets. | |
| Modificada | Alta (10) | 4.5% | — | Vsecurity Tandberg Video Communication Server | 13/4/2010 | 16/6/2026 | The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/secure.php and (2) tandberg/web/user/lib/secure.php, which makes it easier for remote attackers to bypass authentication, and execute arbitrary code by loading a custom… | |
| Modificada | Alta (10) | 69% | — | Blabsoft Bopup Communication Server | 26/6/2009 | 16/6/2026 | Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810. | |
| Modificada | Alta (7.6) | 2.2% | — | Nortel Communication Server 1000Nortel Unistim Protocol | 31/3/2009 | 16/6/2026 | Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attacks. | |
| Modificada | Alta (7.8) | 1.9% | — | Nortel Multimedia Communication Server 5100 | 8/1/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denial of service (device outage) via a UFTP message that has a negative block size or other crafted… | |
| Modificada | Media (6.4) | 1.6% | — | Nortel Multimedia Communication Server 5100 | 8/1/2009 | 16/6/2026 | Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa | Al-enterprise Omnipcx Enterprise Communication Server | 18/9/2007 | 16/6/2026 | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. | |
| Modificada | Alta (7.8) | 1.5% | — | Macromedia Flash Communication Server | 29/11/2005 | 16/6/2026 | Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.8) | 1.7% | — | Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI | 29/11/2005 | 16/6/2026 | Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Media (5) | 83% | — | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 59% | — | Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+15 | 23/12/2004 | 16/6/2026 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number… | |
| Modificada | Alta (7.5) | 3.8% | — | Nortel Business Communications ManagerNortel 802.11 Wireless IP GatewayNortel Succession Communication Server 1000 | 17/2/2004 | 16/6/2026 | Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the… | |
| Modificada | Alta (7.5) | 4.7% | — | Nortel Succession Communication Server 2000 | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. |