Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.5%—Cisco WebnsCisco Content Services Switch 1100012/8/200216/6/2026
The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data.
ModificadaAlta (7.5)6.0%—Microsoft Content Management Server12/8/200216/6/2026
Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
ModificadaAlta (7.5)1.7%—Intel High-bandwidth Digital Content Protection20/11/200116/6/2026
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.
ModificadaAlta (7.5)1.6%—Cisco Content Services Switch 1100014/8/200116/6/2026
The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.
ModificadaAlta (7.5)1.4%—Cisco Content Services Switch 1100014/8/200116/6/2026
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
ModificadaAlta (7.5)5.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaMedia (5)2.8%💥 ExploitNCM Content Management System2/7/200116/6/2026
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.
ModificadaAlta (7.2)0.36%—Cisco Content Services Switch 11050Cisco Content Services Switch 11150Cisco Content Services Switch 1180018/6/200116/6/2026
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.
ModificadaBaja (2.1)0.52%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.
ModificadaBaja (2.1)0.29%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
Orbitaley — Vulnerabilidades