Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.0%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
ModificadaMedia (6.1)1.3%—Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response18/7/201817/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
ModificadaAlta (7.5)2.0%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+97/6/201817/6/2026
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain…
ModificadaCrítica (9.8)6.4%—Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+716/11/201717/6/2026
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration…
ModificadaAlta (8.8)10%💥 ExploitAvaya IP Office Contact Center10/11/201717/6/2026
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
ModificadaMedia (6.1)1.2%—Cisco Unified Contact Center Express4/7/201717/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:…
ModificadaMedia (5.3)2.3%—Cisco Unified Contact Center Enterprise3/5/201717/6/2026
A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is due to the existence of a user account that has an…
ModificadaAlta (8.8)0.63%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center6/10/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
ModificadaMedia (6.1)1.0%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center6/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
ModificadaAlta (7.5)1.3%—Cisco Unified Contact Center ExpressCisco Unified Intelligence Center5/10/201617/6/2026
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
ModificadaMedia (6.1)0.77%—Cisco Unified Contact Center Enterprise23/6/201617/6/2026
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.
ModificadaMedia (6.1)1.1%—Cisco Unified Contact Center Express26/1/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.
ModificadaMedia (4)2.3%—Cisco Unified Contact Center Enterprise18/7/201417/6/2026
Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262.
ModificadaMedia (4)0.76%—Cisco Unified Contact Center EnterpriseCisco Unified Contact Center Express Editor Software29/4/201417/6/2026
The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.
ModificadaMedia (4)1.4%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575.
ModificadaMedia (4)1.3%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCum95536.
ModificadaMedia (6.8)0.82%—Cisco Unified Contact Center Express Editor Software27/2/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502.
ModificadaMedia (5)1.2%—Cisco Unified Contact Center Express Editor Software24/4/201316/6/2026
The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546.
ModificadaMedia (5)2.3%—Cisco Unified Contact Center Express2/5/201216/6/2026
Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.
ModificadaAlta (7.2)1.5%—Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+3113/4/201116/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different…
ModificadaMedia (6.9)0.96%—Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center23/9/201016/6/2026
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote…
ModificadaAlta (7.6)1.1%—Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center23/9/201016/6/2026
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.
ModificadaAlta (7.8)2.9%—Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response10/6/201016/6/2026
Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.
ModificadaAlta (7.8)2.5%—Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response10/6/201016/6/2026
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.