Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

2306 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.87%—Cisco Unified Contact Center Express5/11/202517/6/2026
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are…
AnalizadaCrítica (10)41%💥 ExploitUI Unifi Access31/10/202517/6/2026
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later. Affected Products: UniFi…
AplazadaAlta (7.3)0.24%—UI Unifi Talk TouchAIUI Unifi Talk Touch MAXAIUI Unifi Talk G3AI31/10/202517/6/2026
A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch…
Pendiente de análisisBaja (1.9)0.22%—Drupal Unified Twig ExtensionsAIDrupal Unified Twig EXTAI10/10/202517/6/2026
Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab. The…
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AplazadaAlta (8.4)0.47%—CA Technologies DX Unified Infrastructure ManagementAICA Technologies Nimsoft UIMAI1/10/202517/6/2026
DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
AplazadaAlta (7.5)0.43%—ALL IN ONE MinifierAI11/9/202517/6/2026
The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
AnalizadaAlta (8.8)0.18%—Cisco Unified Communications Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This…
AnalizadaMedia (6.1)0.25%—Cisco Unified Communications Manager IM AND Presence Service3/9/20251/10/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based…
AplazadaAlta (7.2)0.27%—Securden Unified PAM Remote Vendor GatewayAI25/8/202517/6/2026
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.
AplazadaAlta (8.1)0.26%—UI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAIUI Unifi Connect Display Cast LiteAI21/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.10.3 and earlier) UniFi Connect Display Cast Pro (Version 1.0.89 and earlier) UniFi Connect…
AplazadaCrítica (9.8)0.40%—UI Unifi Connect EV Station PROAI21/8/202517/6/2026
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) Mitigation: Update UniFi Connect EV…
AplazadaMedia (4.9)0.25%—UI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAIUI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAI+121/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and…
AplazadaCrítica (9.8)1.2%—UI Unifi Connect EV Station LiteAI21/8/202517/6/2026
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite. Affected Products: UniFi Connect EV Station Lite (Version 1.5.1 and earlier) Mitigation: Update UniFi Connect EV Station Lite…
AplazadaCrítica (9.8)0.52%💥 PoCMitel MicollabAIMitel Nupoint Unified MessagingAI8/8/202517/6/2026
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or…
AplazadaCrítica (9.8)1.2%—UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+24/8/202517/6/2026
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro…
AnalizadaMedia (5.3)0.37%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express16/7/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker…
AnalizadaAlta (8.8)0.44%—Cisco Unified Intelligence CenterCisco Unified Contact Center Express16/7/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could…
AnalizadaCrítica (10)1.2%—Cisco Unified Communications Manager2/7/202517/6/2026
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed…
AplazadaMedia (6.8)0.35%—OpenvpnAIL2tpAIUI Unifi NetworkAI29/6/202517/6/2026
A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.
AnalizadaMedia (6.5)0.39%💥 PoCChangeweb Unifiedtransform4/6/202517/6/2026
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
AnalizadaMedia (6.5)0.36%💥 PoCChangeweb Unifiedtransform4/6/202517/6/2026
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
AnalizadaMedia (4.8)0.26%—Cisco Unified Contact Center Express4/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper sanitization of…
AnalizadaMedia (6.7)0.18%—Cisco FinesseCisco SocialminerCisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence Service+44/6/202517/6/2026
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An…
AnalizadaMedia (6.7)0.17%—Cisco Unified Contact Center Express4/6/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper limitation of a pathname…