Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

2306 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.89%💥 PoCApache Nifi8/5/202617/6/2026
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Script Submission Type, enabling Groovy Script execution in the…
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AplazadaAlta (7.5)0.36%—UI Unifi Play PowerampAIUI Unifi Play Audio PortAI13/4/202617/6/2026
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain UniFi Play WiFi credentials. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version…
AplazadaAlta (7.5)0.43%—UI Unifi Play PowerampAIUI Unifi Play Audio PortAI13/4/202617/6/2026
An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version…
AplazadaCrítica (9.8)0.42%—UI Unifi Play PowerampAIUI Unifi Play Audio PortAI13/4/202617/6/2026
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play…
AplazadaCrítica (9.8)1.1%—UI Unifi Play PowerampAIUI Unifi Play Audio PortAI13/4/202617/6/2026
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24 and earlier) Mitigation: Update UniFi Play PowerAmp to Version…
AplazadaCrítica (9.8)0.77%—UI Unifi Play PowerampAIUI Unifi Play Audio PortAI13/4/202617/6/2026
A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code execution (RCE). Affected Products: UniFi Play PowerAmp (Version 1.0.35 and earlier) UniFi Play Audio Port (Version 1.0.24…
AnalizadaMedia (6.5)0.39%—Cisco Unified Computing System1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could…
AnalizadaMedia (6.5)0.72%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied…
AnalizadaMedia (6.5)0.93%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied…
AnalizadaAlta (8.8)1.1%—Cisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.…
AnalizadaMedia (4.8)0.24%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.24%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.22%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (4.8)0.17%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this…
AnalizadaMedia (6.1)0.18%—Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software1/4/202628/8/2026
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of…
Pendiente de análisisAlta (7.7)0.11%—UI Unifi Network ControllerAI27/3/202617/6/2026
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and…
Pendiente de análisisCrítica (9)0.08%—UI Unifi Network ControllerAIUI UAPAIUI UAP ACAIUI USWAI+127/3/202617/6/2026
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow…
AplazadaAlta (8.8)0.36%—UI Unifi Network ServerAI24/3/202617/6/2026
An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected Products: UniFi Network Server (Version 10.1.85 and earlier) Mitigation: Update UniFi Network Server to Version 10.1.89 or…
AplazadaAlta (7.7)0.55%—UI Unifi Network ApplicationAI19/3/202617/6/2026
An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.
AplazadaCrítica (10)28%💥 ExploitUI Unifi Network ApplicationAI19/3/202617/6/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.
AnalizadaMedia (6.1)0.21%—Cisco Unified Contact Center Express11/3/20268/7/2026
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected…
En análisisMedia (6.1)0.21%—Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI+111/3/202617/6/2026
A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote…
AnalizadaMedia (5.8)0.43%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202618/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete error checking when parsing remote…
AnalizadaMedia (5.8)0.47%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202619/8/2026
This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition…