Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%—Call-cc Chicken31/10/201916/6/2026
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
ModificadaAlta (8.8)4.6%—Call-cc ChickenDebian Linux31/10/201916/6/2026
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
ModificadaMedia (6.5)1.0%—Jenkins Call Remote JOB25/9/201917/6/2026
Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaAlta (8.8)0.91%—Ranksol Live Call Support19/6/201917/6/2026
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
ModificadaAlta (7.5)2.0%—Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 Firmware+123/5/201917/6/2026
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The…
ModificadaCrítica (9.8)3.6%—Activision Call OF Duty\19/4/201917/6/2026
SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of…
ModificadaCrítica (9.8)1.6%—Overit Geocall1/4/201917/6/2026
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.
ModificadaAlta (8.8)1.8%—Overit Geocall1/4/201917/6/2026
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions.
ModificadaAlta (7.5)2.2%—Overit Geocall1/4/201917/6/2026
An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
ModificadaMedia (6.1)0.90%—Overit Geocall1/4/201917/6/2026
Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
ModificadaMedia (4.4)0.34%—Avaya Call Management System Supervisor24/9/201817/6/2026
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
ModificadaMedia (5.3)1.2%—Call Project Call31/5/201817/6/2026
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypassing the route validation rules.
ModificadaCrítica (10)30%💥 ExploitActivision Call OF Duty Modern Warfare 23/5/201817/6/2026
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.
ModificadaAlta (8.8)15%💥 ExploitHP Opencall Media Platform15/2/201817/6/2026
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
ModificadaMedia (6.1)8.0%💥 ExploitHP Opencall Media Platform15/2/201817/6/2026
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
ModificadaMedia (6.1)2.6%💥 ExploitInboundnow Call TO Action11/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to…
ModificadaAlta (7.5)0.94%—Call-cc Chicken17/7/201717/6/2026
Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, will result in O(n) lookup time.
ModificadaAlta (7.5)3.1%—Call-cc Spiffy7/6/201717/6/2026
Directory traversal vulnerability in Spiffy before 5.4.
ModificadaAlta (7.5)1.5%—Call-cc Chicken1/6/201717/6/2026
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.
ModificadaMedia (5.9)0.67%—K-opticom Corporation Business Lala Call28/4/201717/6/2026
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.9)0.67%—K-opticom Corporation Lala Call28/4/201717/6/2026
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.1%—Call-cc Chicken29/3/201717/6/2026
The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).
ModificadaMedia (5.4)0.54%—IBM Call Center FOR Commerce27/3/201717/6/2026
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000442.
ModificadaAlta (8.1)1.5%—Call-cc Chicken16/3/201717/6/2026
An issue was discovered in CHICKEN Scheme through 4.12.0. When using a nonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in unmanaged memory, the vector size would be used in unsanitised form as an argument to malloc(). With an unexpected size, the impact may have been a segfault or buffer overflow.
ModificadaAlta (7.5)1.8%—Call-cc Chicken10/1/201717/6/2026
The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12…
Orbitaley — Vulnerabilidades