Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Logaritmo Aware Callmanager | 30/9/2020 | 17/6/2026 | info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |
| Modificada | Alta (8.8) | 1.1% | — | Logaritmo Aware Callmanager | 21/1/2020 | 17/6/2026 | The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiting a /supervisor/csv/ URI. | |
| Modificada | Media (4) | 1.3% | — | Cisco Unified Callmanager | 28/3/2015 | 17/6/2026 | Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439. | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 28/9/2009 | 16/6/2026 | Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423. | |
| Modificada | Alta (7.1) | 3.2% | — | Cisco Unified CallmanagerCisco Unified Communications ManagerCisco IOS | 26/9/2008 | 16/6/2026 | Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug… | |
| Modificada | Alta (7.1) | 3.5% | — | Cisco Unified CallmanagerCisco Unified Communications ManagerCisco IOS | 26/9/2008 | 16/6/2026 | Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug… | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 16/5/2008 | 16/6/2026 | The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770. | |
| Modificada | Media (6.5) | 1.9% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 14/2/2008 | 16/6/2026 | SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages. | |
| Modificada | Alta (10) | 57% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 17/1/2008 | 16/6/2026 | Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code… | |
| Modificada | Alta (10) | 5.5% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 18/10/2007 | 16/6/2026 | Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames,… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 18/10/2007 | 16/6/2026 | Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822. | |
| Modificada | Alta (10) | 8.9% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 15/7/2007 | 16/6/2026 | Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 9.6% | — | Cisco Unified CallmanagerCisco Unified Communications Manager | 15/7/2007 | 16/6/2026 | Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 2.4% | — | Cisco Unified Callmanager | 3/4/2007 | 16/6/2026 | The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Unified CallmanagerCisco Unified Presence Server | 3/4/2007 | 16/6/2026 | Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698. | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Unified CallmanagerCisco Unified Presence Server | 2/4/2007 | 16/6/2026 | Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a "specific UDP packet" to UDP port 8500, aka bug ID… | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco Security AgentCisco Unified CallmanagerCisco Unified Presence Server | 26/10/2006 | 16/6/2026 | Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certain options. | |
| Modificada | Media (5) | 1.6% | — | Cisco Callmanager Express | 9/8/2006 | 16/6/2026 | Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417. | |
| Modificada | Media (4.6) | 0.81% | — | Cisco Unified Callmanager | 18/7/2006 | 16/6/2026 | Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bug CSCse11005. | |
| Modificada | Alta (7.5) | 3.6% | — | Cisco Unified Callmanager | 18/7/2006 | 16/6/2026 | Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542. | |
| Modificada | Media (4) | 1.0% | — | Cisco Unified Callmanager | 18/7/2006 | 16/6/2026 | The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704. | |
| Modificada | Media (5) | 3.9% | — | Cisco CallmanagerAI | 12/7/2005 | 16/6/2026 | Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe). | |
| Modificada | Alta (7.5) | 1.6% | — | Matthew Redman Allmanage | 13/5/2000 | 16/6/2026 | The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages. | |
| Modificada | Alta (7.5) | 1.4% | — | Matthew Redman Allmanage | 13/5/2000 | 16/6/2026 | The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers. |