Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | — | Emerson Network Power Avocent Mergepoint Unity 2016 Firmware | 24/1/2014 | 16/6/2026 | Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file. | |
| Modificada | Alta (7.1) | 1.8% | — | ATT StatusHTC ChachaHTC DesireHTC Merge+5 | 21/8/2012 | 16/6/2026 | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain… | |
| Modificada | Media (5) | 1.2% | — | Cisco Emergency Responder | 6/8/2012 | 16/6/2026 | Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the CERPT port, aka Bug ID CSCtx38369. | |
| Modificada | Media (5) | 1.3% | — | Linearcorp Emerge 50Linearcorp Emerge 5000 | 25/6/2010 | 16/6/2026 | The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device. | |
| Modificada | Alta (10) | 1.7% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password. | |
| Modificada | Media (5) | 1.4% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests. | |
| Modificada | Media (5) | 1.9% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames. | |
| Modificada | Media (5) | 2.5% | — | S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess | 25/6/2010 | 16/6/2026 | The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests. | |
| Modificada | Media (5) | 1.8% | — | S2sys Linear Emerge Access Control System | 5/1/2010 | 16/6/2026 | Unspecified vulnerability in the management console in the S2 Security Linear eMerge Access Control System 2.5.x allows remote attackers to cause a denial of service (configuration reset) via a request to a crafted URI. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Eduforge Emergecolab | 28/1/2009 | 16/6/2026 | Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php. | |
| Modificada | Alta (10) | 5.1% | — | Cisco Emergency ResponderCisco Mobility ManagerCisco Unified Communications ManagerCisco Unified Presence | 4/4/2008 | 16/6/2026 | The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Oxfam Australia Emergencies Personnel Information System | 12/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter. | |
| Modificada | Baja (2.1) | 0.38% | — | Peters Software Lettermerger | 6/3/2006 | 16/6/2026 | LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4) | 1.9% | — | E-merge Winace | 3/3/2006 | 16/6/2026 | Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5.1) | 3.2% | — | E-merge Unace | 22/2/2005 | 16/6/2026 | Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | E-merge Unace | 22/2/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames. | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Alta (7.5) | 1.3% | — | Granite Software Zmerge | 4/10/2002 | 16/6/2026 | The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts. | |
| Modificada | Alta (7.5) | 1.6% | — | Emergenices Personnel Information System Empris | 2/10/2001 | 16/6/2026 | Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. |