Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—NCH Axon PBX25/7/202117/6/2026
NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
ModificadaMedia (6.5)1.2%—NCH Axon PBX25/7/202117/6/2026
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
ModificadaMedia (5.4)0.62%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
ModificadaMedia (5.4)0.62%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
ModificadaMedia (5.4)0.62%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
ModificadaMedia (5.4)0.59%—Nchsoftware Axon PBX25/7/202117/6/2026
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
ModificadaMedia (6.1)29%—NCH Axon PBX1/6/201817/6/2026
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
ModificadaAlta (7.8)2.5%—NCH Axon PBX1/6/201817/6/2026
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.
Orbitaley — Vulnerabilidades