Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.76% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 6/7/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service | 6/7/2022 | 17/6/2026 | A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker… | |
| Modificada | Media (5.3) | 1.0% | — | Cisco Unified Communications ManagerCisco Unity Connection | 6/7/2022 | 17/6/2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system… | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Carrcommunications Rsvpmaker | 13/6/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Alibaba FastjsonOracle Communications Cloud Native Core Unified Data Repository | 10/6/2022 | 17/6/2026 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable… | |
| Modificada | Alta (7.5) | 1.9% | — | Carrcommunications Rsvpmaker | 10/5/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database… | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Carrcommunications Rsvpmaker | 10/5/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in… | |
| Modificada | Media (5.5) | 1.5% | — | RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 27/4/2022 | 17/6/2026 | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional… | |
| Modificada | Alta (7.8) | 2.3% | — | RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 27/4/2022 | 17/6/2026 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution… | |
| Modificada | Media (6.5) | 1.3% | — | Pivotal Spring Security OauthOracle Communications Design Studio | 21/4/2022 | 17/6/2026 | <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the… | |
| Modificada | Media (6.5) | 0.35% | — | Cisco Unified Communications Manager | 21/4/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service… | |
| Modificada | Media (6.5) | 1.9% | — | Cisco Unified Communications Manager | 21/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Unified Communications Manager | 21/4/2022 | 17/6/2026 | A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system. This vulnerability is due to improper… | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Unified Communications ManagerCisco Unity Connection | 21/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… | |
| Modificada | Media (6.8) | 0.46% | — | Cisco Unified Communications Manager | 21/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This… | |
| Modificada | Alta (8.1) | 0.84% | — | Cisco Unified Communications Manager IM AND Presence Service | 21/4/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted… | |
| Modificada | Crítica (10) | 2.1% | — | Oracle Communications Billing AND Revenue Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to… | |
| Modificada | Alta (8.5) | 1.2% | — | Oracle Communications Billing AND Revenue Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to… | |
| Modificada | Alta (8.3) | 1.3% | — | Oracle Communications Billing AND Revenue Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle… | |
| Modificada | Alta (7.5) | 1.0% | — | Oracle Communications Billing AND Revenue Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Alta (7.8) | 1.5% | — | VIMFedoraproject FedoraDebian LinuxOracle Communications Cloud Native Core Network Exposure Function | 30/3/2022 | 17/6/2026 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | |
| Modificada | Media (5.5) | 0.30% | — | Linux KernelFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure Function+1 | 25/3/2022 | 17/6/2026 | A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS). | |
| Modificada | Media (6.8) | 1.7% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Element Software+12 | 25/3/2022 | 17/6/2026 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information. |