Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.90% | — | Videowhisper 2way Videocalls AND Random Chat | 16/8/2021 | 17/6/2026 | The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7. | |
| Modificada | Media (5.3) | 0.81% | — | Samsung Smart Touch Call | 5/8/2021 | 17/6/2026 | Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview. | |
| Modificada | Alta (7.3) | 0.35% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please… | |
| Modificada | Alta (7.3) | 0.26% | — | Trendmicro Housecall FOR Home Networks | 12/5/2021 | 17/6/2026 | An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that… | |
| Modificada | Media (6.5) | 0.98% | — | Avaya Callback Assist | 23/4/2021 | 17/6/2026 | An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7. | |
| Modificada | Media (6.1) | 3.2% | — | Linkedin Oncall | 5/2/2021 | 17/6/2026 | LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar. | |
| Modificada | Alta (7.8) | 0.75% | — | Trendmicro Housecall FOR Home Networks | 27/1/2021 | 17/6/2026 | A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the machine to exploit this vulnerability. | |
| Modificada | Alta (8.8) | 4.9% | 💥 PoC | Macally Wifisd2-2a82 Firmware | 14/12/2020 | 17/6/2026 | In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user… | |
| Modificada | Alta (7.5) | 1.3% | — | Logaritmo Aware Callmanager | 30/9/2020 | 17/6/2026 | info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |
| Modificada | Media (5.4) | 0.72% | — | Recall-products Project Recall-products | 14/9/2020 | 17/6/2026 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed. | |
| Modificada | Alta (8.8) | 1.9% | — | Recall-products Project Recall-products | 14/9/2020 | 17/6/2026 | Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query. | |
| Modificada | Crítica (9.8) | 2.2% | — | Activision Call OF Duty Modern Warfare 2 | 30/6/2020 | 17/6/2026 | An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJoinPartyRequest has a buffer overflow vulnerability and can be exploited by using a crafted joinParty packet. This can be utilized to conduct arbitrary code execution on a victim's machine. | |
| Modificada | Media (5.4) | 0.56% | — | Eleveo Call Recording | 27/4/2020 | 17/6/2026 | ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role Add form, (4) name or number field in the Edit Group form, (5) tagKey or tagValue field in the Recording Rules… | |
| Modificada | Media (6.9) | 0.80% | — | HPE Opencall Media Platform | 16/4/2020 | 17/6/2026 | Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For OCMP version 4.4.X - please upgrade to… | |
| Modificada | Alta (8.8) | 1.4% | — | Eleveo Call Recording | 14/4/2020 | 17/6/2026 | A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elevate privileges to root by abusing the callrec-rs@.service. The callrec-rs@.service starts the /opt/callrec/bin/rs binary with root… | |
| Modificada | Alta (8.8) | 3.1% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+29 | 5/2/2020 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages.… | |
| Modificada | Alta (8.8) | 1.1% | — | Logaritmo Aware Callmanager | 21/1/2020 | 17/6/2026 | The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI. | |
| Modificada | Alta (7.8) | 0.56% | — | Trendmicro Housecall FOR Home Networks | 18/12/2019 | 17/6/2026 | Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses. | |
| Modificada | Alta (7.8) | 0.56% | — | Trendmicro Housecall FOR Home Networks | 18/12/2019 | 17/6/2026 | A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges. | |
| Modificada | Crítica (9.8) | 4.7% | — | Call-cc ChickenDebian Linux | 22/11/2019 | 17/6/2026 | Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function. | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Alta (8.8) | 2.2% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. NOTE: this issue exists because of an incomplete fix for CVE-2012-6122. | |
| Modificada | Crítica (9.8) | 1.8% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. | |
| Modificada | Media (5.3) | 1.3% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)." | |
| Modificada | Media (6.5) | 1.3% | — | Call-cc ChickenDebian Linux | 31/10/2019 | 16/6/2026 | Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." |