Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967. | |
| Modificada | Media (6.1) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified IP Interactive Voice Response | 18/7/2018 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+9 | 7/6/2018 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain… | |
| Modificada | Crítica (9.8) | 6.4% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+7 | 16/11/2017 | 17/6/2026 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration… | |
| Modificada | Alta (8.8) | 10% | 💥 Exploit | Avaya IP Office Contact Center | 10/11/2017 | 17/6/2026 | Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Unified Contact Center Express | 4/7/2017 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases:… | |
| Modificada | Media (5.3) | 2.3% | — | Cisco Unified Contact Center Enterprise | 3/5/2017 | 17/6/2026 | A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is due to the existence of a user account that has an… | |
| Modificada | Alta (8.8) | 0.63% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 6/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 5/10/2016 | 17/6/2026 | The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Unified Contact Center Enterprise | 23/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650. | |
| Modificada | Media (6.1) | 1.1% | — | Cisco Unified Contact Center Express | 26/1/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033. | |
| Modificada | Media (4) | 2.3% | — | Cisco Unified Contact Center Enterprise | 18/7/2014 | 17/6/2026 | Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262. | |
| Modificada | Media (4) | 0.76% | — | Cisco Unified Contact Center EnterpriseCisco Unified Contact Center Express Editor Software | 29/4/2014 | 17/6/2026 | The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133. | |
| Modificada | Media (4) | 1.4% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575. | |
| Modificada | Media (4) | 1.3% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCum95536. | |
| Modificada | Media (6.8) | 0.82% | — | Cisco Unified Contact Center Express Editor Software | 27/2/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502. | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Contact Center Express Editor Software | 24/4/2013 | 16/6/2026 | The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546. | |
| Modificada | Media (5) | 2.3% | — | Cisco Unified Contact Center Express | 2/5/2012 | 16/6/2026 | Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (6.9) | 0.96% | — | Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center | 23/9/2010 | 16/6/2026 | The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote… | |
| Modificada | Alta (7.6) | 1.1% | — | Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center | 23/9/2010 | 16/6/2026 | The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe. | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295. | |
| Modificada | Alta (7.8) | 2.5% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message. |