Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | NCH Axon PBX | 25/7/2021 | 17/6/2026 | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring. | |
| Modificada | Media (6.5) | 1.2% | — | NCH Axon PBX | 25/7/2021 | 17/6/2026 | NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring. | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected). | |
| Modificada | Media (5.4) | 0.62% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored). | |
| Modificada | Media (5.4) | 0.62% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored). | |
| Modificada | Media (5.4) | 0.62% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored). | |
| Modificada | Media (5.4) | 0.59% | — | Nchsoftware Axon PBX | 25/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored). | |
| Modificada | Media (6.1) | 29% | — | NCH Axon PBX | 1/6/2018 | 17/6/2026 | There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application. | |
| Modificada | Alta (7.8) | 2.5% | — | NCH Axon PBX | 1/6/2018 | 17/6/2026 | AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly. |