Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.4%—Cisco Unified IP Phone FirmwareCisco IP Phone Firmware7/6/201817/6/2026
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit…
ModificadaAlta (7.5)2.5%—Cisco IP Phone Firmware7/6/201817/6/2026
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS)…
ModificadaCrítica (9.8)1.5%—Ismartalarm Cubeone Firmware1/12/201717/6/2026
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
ModificadaAlta (7.5)0.44%—Ismartalarm Cubeone Firmware1/12/201717/6/2026
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
ModificadaMedia (5.5)0.65%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access…
ModificadaMedia (5.5)0.65%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to cause to any memory access…
ModificadaMedia (6.1)0.52%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter and cause to memory out-of-bound read.
ModificadaAlta (7.8)0.64%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a arbitrary memory write vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific…
ModificadaAlta (7.8)0.64%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter…
ModificadaAlta (7.8)0.81%—Huawei MTK Platform Smart Phone Firmware22/11/201717/6/2026
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter…
ModificadaAlta (7.5)2.3%—Cisco Small Business IP Phone Firmware19/10/201717/6/2026
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the…
ModificadaAlta (7.5)1.3%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
ModificadaAlta (7.5)0.69%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
ModificadaCrítica (9.8)3.5%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
ModificadaAlta (7.5)0.73%—Ismartalarm Cubeone Firmware11/7/201717/6/2026
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
ModificadaAlta (7.8)0.89%—Huawei P8 Smartphone Firmware2/8/201617/6/2026
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.
ModificadaAlta (7.3)0.84%—Huawei P8 Smartphone Firmware2/8/201617/6/2026
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.
ModificadaMedia (5)5.2%💥 ExploitYealink Voip Phone Firmware16/7/201417/6/2026
CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.
ModificadaMedia (4.3)1.9%—Yealink Voip Phone FirmwareYealink Voip Phone16/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.
ModificadaMedia (6.6)0.28%—Cisco Unified IP Phone FirmwareCisco Unified IP Phone 8961Cisco Unified IP Phone 9951Cisco Unified IP Phone 997113/11/201317/6/2026
The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
ModificadaAlta (7.8)3.2%—Cisco Unified IP Phone 8945Cisco Unified IP Phone Firmware29/8/201316/6/2026
The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270.
ModificadaMedia (4.3)0.94%—Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+1413/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,…
ModificadaAlta (7.1)3.2%—Linux KernelAvaya 96x1 IP Deskphone Firmware17/5/201216/6/2026
The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.
ModificadaMedia (4.6)0.41%—Cisco Unified IP PhoneCisco Unified IP Phone Firmware3/5/201216/6/2026
Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237.
ModificadaMedia (5)1.1%—Cisco Small Business IP Phone FirmwareCisco Small Business IP Phone2/5/201216/6/2026
Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768.