Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.52% | — | Carrcommunications RsvpmakerAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7. | |
| Aplazada | Media (4.9) | 0.38% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAI | 11/3/2025 | 17/6/2026 | SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or… | |
| Aplazada | Media (5.3) | 0.29% | — | Carrcommunications RsvpmakerAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5. | |
| Analizada | Media (5.3) | 0.38% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (5.4) | 0.26% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (6.3) | 0.19% | — | Oracle Communications Order AND Service Management | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Aplazada | Alta (8.7) | 0.49% | — | Belledonne Communications Linphone-desktopAI | 17/1/2025 | 17/6/2026 | Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition. | |
| Aplazada | Media (5.1) | 0.29% | — | Cpci85 Central Processing CommunicationAI | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element… | |
| Aplazada | Alta (7.1) | 0.16% | — | Ringcentral CommunicationsAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pbmacintyre RingCentral Communications rccp-free allows Stored XSS.This issue affects RingCentral Communications: from n/a through <= 1.7.0. | |
| Aplazada | Media (6.1) | 0.50% | — | Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAICisco Unified Communications Manager IM AND Presence ServiceAICisco Unity ConnectionAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker… | |
| Analizada | Media (5.4) | 0.42% | — | Cisco Unified Communications Manager | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Alta (7.4) | 0.64% | — | Cisco Telepresence Video Communication Server | 15/11/2024 | 17/6/2026 | A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. | |
| Analizada | Alta (7.4) | 0.91% | — | Cisco Telepresence Video Communication Server | 15/11/2024 | 17/6/2026 | A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Unified Communications Manager | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Media (6.5) | 0.44% | — | Cisco Unified Communications Manager IM AND Presence Service | 6/11/2024 | 17/6/2026 | A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of unencrypted credentials in… | |
| Modificada | Crítica (9.8) | 0.51% | — | Carrcommunications Rsvpmaker | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication. | |
| Aplazada | Alta (8.8) | 1.7% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Fujian Kelixin Communication Command AND Dispatch PlatformAI | 8/10/2024 | 17/6/2026 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php. | |
| Analizada | Media (6.7) | 0.55% | — | Cisco Telepresence Video Communication Server | 2/10/2024 | 17/6/2026 | A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have Administrator-level credentials with read-write… | |
| Analizada | Media (5.4) | 0.42% | — | Millbeckcommunications Proroute H685t-w Firmware | 17/9/2024 | 17/6/2026 | This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser session. | |
| Analizada | Media (6.1) | 0.37% | — | Cisco Unified Communications Manager | 21/8/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.… | |
| Analizada | Alta (7.5) | 0.74% | — | Cisco Unified Communications Manager | 21/8/2024 | 17/6/2026 | A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Analizada | Media (4.7) | 0.38% | — | Cisco Telepresence Video Communication Server | 17/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting… | |
| Aplazada | Media (4.6) | 0.19% | — | Gallagher Controller 6000AIGallagher Controller 7000AIGallagher Aperio Communication HUBAI | 11/7/2024 | 17/6/2026 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks connected via Aperio Communication Hubs to momentarily allow free access. This issue affects: Gallagher Controller 6000 and 7000 9.10 prior to… |