Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.5%—Sweetscape 010 Editor22/7/201917/6/2026
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.
ModificadaMedia (5.5)2.1%—Sweetscape 010 Editor22/7/201917/6/2026
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
ModificadaAlta (7.5)1.2%—Sweetscape 010 Editor5/6/201917/6/2026
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.
ModificadaAlta (7.5)1.2%—Sweetscape 010 Editor5/6/201917/6/2026
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.
ModificadaCrítica (9.8)2.4%—Sweetscape 010 Editor5/6/201917/6/2026
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.
ModificadaAlta (7.8)1.7%—Hornerautomation Cscape28/2/201917/6/2026
Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and remotely execute arbitrary code.
ModificadaCrítica (9.8)3.6%—SAP Landscape Management15/2/201917/6/2026
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).
ModificadaMedia (6.1)1.4%—Netscape Enterprise Server31/1/201917/6/2026
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is…
ModificadaAlta (7.5)1.7%—SAP Landscape Management8/1/201917/6/2026
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.
ModificadaAlta (7.8)1.7%—Hornerautomation Cscape20/12/201817/6/2026
Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be exploited by processing specially crafted POC files lacking user input validation. This may allow an attacker to read confidential information and remotely execute arbitrary code.
ModificadaMedia (4.9)1.2%—Unify Openstage SIPUnify Openscape Desk Phone IP SIP12/4/201817/6/2026
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access the debug port using the serial interface via the ssh-password…
ModificadaAlta (8.1)1.6%—Unify Openstage SIPUnify Openscape Desk Phone IP SIP12/4/201817/6/2026
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
ModificadaAlta (7.5)1.8%—Unify Openstage SIPUnify Openscape Desk Phone IP SIP12/4/201817/6/2026
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4) conversion_java2native.sh, (5) coreCompression.sh, (6)…
ModificadaCrítica (9.8)1.2%—Unify Openscape Deployment Service19/3/201817/6/2026
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.4)0.64%—Cisco Videoscape Anyres Live8/3/201817/6/2026
A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of…
ModificadaCrítica (9.8)2.5%—SAP Netweaver System Landscape Directory1/3/201817/6/2026
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
ModificadaAlta (8.8)0.58%—Userscape Helpspot19/2/201817/6/2026
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account.
ModificadaMedia (6.1)0.89%—Userscape Helpspot19/2/201817/6/2026
An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked.
ModificadaMedia (5.9)1.3%—Unify Openstage 60 FirmwareUnify Openscape Desk Phone IP 55G SIP FirmwareUnify Openstage 15 FirmwareUnify Openstage 20E Firmware+625/9/201717/6/2026
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenStage 15, 20E, 20, and 40 and OpenScape Desk Phone IP 35G HFA V3, and OpenScape Desk Phone IP 35G…
ModificadaAlta (7.5)1.7%—Cisco Videoscape Distribution Suite FOR Television7/8/201717/6/2026
A vulnerability in the cache server within Cisco Videoscape Distribution Suite (VDS) for Television 3.2(5)ES1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted appliance. The vulnerability is due to excessive mapped connections exhausting the allotted resources…
ModificadaMedia (6.1)0.85%—Cisco Videoscape Distribution Suite Service Manager5/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552.
ModificadaAlta (8.6)3.1%—Mozilla Netscape Portable Runtime7/8/201617/6/2026
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
ModificadaMedia (6.5)0.59%—Cisco Videoscape Session Resource Manager28/7/201617/6/2026
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
ModificadaMedia (5.3)1.7%—Cisco Videoscape Distribution Suite FOR Internet Streaming1/3/201617/6/2026
The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN…
ModificadaMedia (6.5)0.95%—Cisco Videoscape Distribution Suite Service Manager12/12/201517/6/2026
Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025.
Orbitaley — Vulnerabilidades