Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.5% | — | Sweetscape 010 Editor | 22/7/2019 | 17/6/2026 | In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service. | |
| Modificada | Media (5.5) | 2.1% | — | Sweetscape 010 Editor | 22/7/2019 | 17/6/2026 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Sweetscape 010 Editor | 5/6/2019 | 17/6/2026 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application. | |
| Modificada | Alta (7.5) | 1.2% | — | Sweetscape 010 Editor | 5/6/2019 | 17/6/2026 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application. | |
| Modificada | Crítica (9.8) | 2.4% | — | Sweetscape 010 Editor | 5/6/2019 | 17/6/2026 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution. | |
| Modificada | Alta (7.8) | 1.7% | — | Hornerautomation Cscape | 28/2/2019 | 17/6/2026 | Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 3.6% | — | SAP Landscape Management | 15/2/2019 | 17/6/2026 | Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)). | |
| Modificada | Media (6.1) | 1.4% | — | Netscape Enterprise Server | 31/1/2019 | 17/6/2026 | servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is… | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Landscape Management | 8/1/2019 | 17/6/2026 | Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (7.8) | 1.7% | — | Hornerautomation Cscape | 20/12/2018 | 17/6/2026 | Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be exploited by processing specially crafted POC files lacking user input validation. This may allow an attacker to read confidential information and remotely execute arbitrary code. | |
| Modificada | Media (4.9) | 1.2% | — | Unify Openstage SIPUnify Openscape Desk Phone IP SIP | 12/4/2018 | 17/6/2026 | CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access the debug port using the serial interface via the ssh-password… | |
| Modificada | Alta (8.1) | 1.6% | — | Unify Openstage SIPUnify Openscape Desk Phone IP SIP | 12/4/2018 | 17/6/2026 | The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack. | |
| Modificada | Alta (7.5) | 1.8% | — | Unify Openstage SIPUnify Openscape Desk Phone IP SIP | 12/4/2018 | 17/6/2026 | Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4) conversion_java2native.sh, (5) coreCompression.sh, (6)… | |
| Modificada | Crítica (9.8) | 1.2% | — | Unify Openscape Deployment Service | 19/3/2018 | 17/6/2026 | SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.4) | 0.64% | — | Cisco Videoscape Anyres Live | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of… | |
| Modificada | Crítica (9.8) | 2.5% | — | SAP Netweaver System Landscape Directory | 1/3/2018 | 17/6/2026 | SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity. | |
| Modificada | Alta (8.8) | 0.58% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | |
| Modificada | Media (6.1) | 0.89% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked. | |
| Modificada | Media (5.9) | 1.3% | — | Unify Openstage 60 FirmwareUnify Openscape Desk Phone IP 55G SIP FirmwareUnify Openstage 15 FirmwareUnify Openstage 20E Firmware+6 | 25/9/2017 | 17/6/2026 | OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenStage 15, 20E, 20, and 40 and OpenScape Desk Phone IP 35G HFA V3, and OpenScape Desk Phone IP 35G… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Television | 7/8/2017 | 17/6/2026 | A vulnerability in the cache server within Cisco Videoscape Distribution Suite (VDS) for Television 3.2(5)ES1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted appliance. The vulnerability is due to excessive mapped connections exhausting the allotted resources… | |
| Modificada | Media (6.1) | 0.85% | — | Cisco Videoscape Distribution Suite Service Manager | 5/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. | |
| Modificada | Alta (8.6) | 3.1% | — | Mozilla Netscape Portable Runtime | 7/8/2016 | 17/6/2026 | Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function. | |
| Modificada | Media (6.5) | 0.59% | — | Cisco Videoscape Session Resource Manager | 28/7/2016 | 17/6/2026 | Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Internet Streaming | 1/3/2016 | 17/6/2026 | The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN… | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Videoscape Distribution Suite Service Manager | 12/12/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025. |