Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.39%—SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI8/9/20268/9/2026
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could…
AplazadaAlta (7.5)0.54%—SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI9/12/202517/6/2026
SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.
AplazadaMedia (4.9)0.38%—SAP WEB DispatcherAISAP Internet Communication ManagerAI11/3/202517/6/2026
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or…
ModificadaMedia (6.7)0.20%—Avaya Aura Communication Manager12/10/202217/6/2026
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
ModificadaMedia (4.3)0.55%—SAP WEB DispatcherSAP Internet Communication Manager14/7/202117/6/2026
SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73, WEBDISP 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, KERNEL 7.21, 7.22,…
ModificadaAlta (8.8)0.43%—Avaya Aura Communication ManagerAvaya Aura Messaging11/8/202017/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the…
ModificadaAlta (7.5)1.5%—SAP Netweaver Internet Communication Manager (kernel)SAP Netweaver Internet Communication Manager (krnl32nuc)SAP Netweaver Internet Communication Manager (krnl32uc)SAP Netweaver Internet Communication Manager (krnl64nuc)+114/1/202017/6/2026
Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an attacker to prevent users from accessing its services through a denial of service.
ModificadaAlta (7.5)2.3%—Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+2315/11/201917/6/2026
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ModificadaAlta (7.5)2.2%—Avaya Aura Communication Manager1/2/201917/6/2026
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
ModificadaMedia (6.7)0.30%—Avaya Aura Communication Manager27/9/201817/6/2026
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
ModificadaAlta (8.1)17%—Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+630/9/201016/6/2026
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked…
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+921/9/201016/6/2026
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the…
ModificadaAlta (7.8)0.41%—Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+118/9/201016/6/2026
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by…
ModificadaAlta (7.8)0.43%—Linux KernelVmware ESXAvaya Aura Communication ManagerAvaya Aura Presence Services+58/9/201016/6/2026
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
ModificadaAlta (7.1)0.44%—Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+1416/11/200916/6/2026
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
ModificadaAlta (9)2.4%—Avaya Communication Manager10/4/200916/6/2026
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."
ModificadaAlta (9)2.1%—Avaya Communication Manager10/4/200916/6/2026
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."
ModificadaAlta (9)2.4%—Avaya SIP Enablement ServicesAvaya Communication Manager10/4/200916/6/2026
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."
ModificadaAlta (9)2.1%—Avaya Communication ManagerAvaya SIP Enablement Services10/4/200916/6/2026
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."
ModificadaMedia (6.4)1.5%—Avaya SIP Enablement ServicesAvaya Communication Manager10/4/200916/6/2026
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate…
ModificadaAlta (7.8)2.3%—Avaya SIP Enablement ServicesAvaya Communication Manager10/4/200916/6/2026
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system…
ModificadaMedia (6.8)1.3%—Avaya Communication Manager1/4/200916/6/2026
Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource consumption) via unknown vectors.
ModificadaAlta (7.5)1.4%—Avaya Communication Manager1/4/200916/6/2026
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors related to reuse of valid credentials.
ModificadaMedia (6.8)1.5%—Avaya Communication Manager1/4/200916/6/2026
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow…
ModificadaMedia (5)1.4%—Avaya Communication Manager24/12/200816/6/2026
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers to read (1) configuration files, (2) log files, (3) binary image files, and (4) help files via unknown vectors.