Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.66% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015. | |
| Modificada | Alta (8.8) | 1.4% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012. | |
| Modificada | Alta (8.8) | 2.0% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 could allow an authenciated user to create arbitrary users which could cause ID management issues and result in code execution. IBM X-Force ID: 157011. | |
| Modificada | Alta (7.5) | 1.7% | — | Merge Project Merge | 30/10/2018 | 17/6/2026 | The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack. | |
| Modificada | Media (5.4) | 1.2% | — | Cisco Unified Communications ManagerCisco Unity ConnectionCisco Unified Communications Manager IM AND Presence ServiceCisco Emergency Responder | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper… | |
| Modificada | Crítica (9.8) | 1.4% | — | Merge-object Project Merge-object | 3/7/2018 | 17/6/2026 | The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. | |
| Modificada | Crítica (9.8) | 1.4% | — | Merge-options Project Merge-options | 3/7/2018 | 17/6/2026 | The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. | |
| Modificada | Crítica (9.8) | 1.4% | — | Umbraengineering Merge-recursive | 3/7/2018 | 17/6/2026 | The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration Mediation FulfillmentCisco Mediasense+9 | 7/6/2018 | 17/6/2026 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain… | |
| Modificada | Alta (8.8) | 2.0% | — | Merge-deep Project Merge-deep | 7/6/2018 | 17/6/2026 | merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. | |
| Modificada | Crítica (9.8) | 4.2% | — | Nortekcontrol Emerge E3 Firmware | 19/2/2018 | 17/6/2026 | A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior. A remote attacker may be able to execute arbitrary code on a target machine with elevated privileges. | |
| Modificada | Crítica (9.8) | 6.4% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+7 | 16/11/2017 | 17/6/2026 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration… | |
| Modificada | Media (5.4) | 0.97% | — | Cisco Emergency Responder | 7/9/2017 | 17/6/2026 | A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this… | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.6% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "loose comparison false positives." | |
| Modificada | Alta (7.5) | 2.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name. | |
| Modificada | Alta (7.4) | 1.7% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.1% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import." | |
| Modificada | Alta (7.5) | 2.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories. | |
| Modificada | Media (6.5) | 1.7% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.2% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy. | |
| Modificada | Media (5.3) | 1.8% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails. |