Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 0.66% | — | Cisco Telepresence Video Communication Server | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway… | |
| Modificada | Media (5.7) | 0.60% | — | Cisco Unified Communications Manager | 28/6/2023 | 17/6/2026 | A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Unified Communications Manager IM AND Presence Service | 28/6/2023 | 17/6/2026 | A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are attempting to authenticate to the service,… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Telepresence Video Communication Server | 28/6/2023 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling… | |
| Modificada | Media (6.1) | 0.46% | — | Exelysis Unified Communications Solution | 17/5/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Exelysis Unified Communication Solution (EUCS) v.1.0 allows a remote attacker to gain privileges via the URL path of the eucsAdmin login web page. | |
| Modificada | Media (6.1) | 0.64% | — | Exelysis Unified Communications Solution | 26/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form. | |
| Modificada | Media (5.3) | 1.3% | 💥 PoC | Oracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+2 | 18/4/2023 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Modificada | Alta (7.5) | 0.94% | — | Siemens Siprotec 5 6md85 FirmwareSiemens Siprotec 5 6md86 FirmwareSiemens Siprotec 5 6md89 FirmwareSiemens Siprotec 5 6mu85 Firmware+35 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.64), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80… | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Apsystems Energy Communication Unit Firmware | 14/3/2023 | 17/6/2026 | OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php. | |
| Modificada | Alta (7.3) | 0.18% | — | Intel Oneapi Collective Communications Library | 16/2/2023 | 17/6/2026 | Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.90% | — | Cisco Unified Communications Manager | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists… | |
| Modificada | Crítica (9.8) | 0.84% | — | Oracle Communications Converged Application Server | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Communications… | |
| Modificada | Alta (8.8) | 0.63% | — | Oracle Communications Convergence | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration). The supported version that is affected is 3.0.3.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications… | |
| Modificada | Media (5.3) | 1.1% | — | Oracle Communications Unified AssuranceOracle GraalvmOracle JDKOracle JRE+1 | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf; Oracle GraalVM Enterprise Edition: 20.3.8 and 21.3.4. Easily exploitable vulnerability allows unauthenticated attacker… | |
| Modificada | Media (4.4) | 0.21% | — | Oracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Policy | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Siprotec 5 6md85 FirmwareSiemens Siprotec 5 6md86 FirmwareSiemens Siprotec 5 6md89 FirmwareSiemens Siprotec 5 6mu85 Firmware+30 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.50), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.50), SIPROTEC 5 6MD89 (CP300) (All versions < V9.64),… | |
| Modificada | Media (6.5) | 0.67% | — | Oracle Communications Billing AND Revenue Management | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to… | |
| Modificada | Media (6.7) | 0.20% | — | Avaya Aura Communication Manager | 12/10/2022 | 17/6/2026 | Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0. | |
| Modificada | Alta (7.8) | 0.40% | — | Autodesk Advanced Material ExchangeAutodesk Moldflow AdviserAutodesk Moldflow CommunicatorAutodesk Moldflow Synergy | 3/10/2022 | 17/6/2026 | A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (8.1) | 1.3% | — | Cisco Unified Communications Manager | 10/8/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists… | |
| Modificada | Media (5.3) | 1.0% | — | Oracle Communications Billing AND Revenue Management | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (6.5) | 0.78% | — | Oracle Communications Billing AND Revenue Management | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (5.4) | 0.46% | — | Oracle Communications Billing AND Revenue Management | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (8.1) | 1.4% | — | Oracle Communications Billing AND Revenue Management | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Unified Communications Manager | 6/7/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device.… |