Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.59%—Altitude Authentication ServiceAIAltitude Communication ServerAI26/1/202617/6/2026
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior…
AplazadaMedia (6.9)0.43%—Altitude Communication ServerAI26/1/202617/6/2026
Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request…
AplazadaAlta (8.8)0.14%—Bizerba Communication ServerAI31/10/202517/6/2026
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
AnalizadaAlta (7.4)0.64%—Cisco Telepresence Video Communication Server15/11/202417/6/2026
A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
AnalizadaAlta (7.4)0.91%—Cisco Telepresence Video Communication Server15/11/202417/6/2026
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device…
AnalizadaMedia (6.7)0.55%—Cisco Telepresence Video Communication Server2/10/202417/6/2026
A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have Administrator-level credentials with read-write…
AnalizadaMedia (4.7)0.38%—Cisco Telepresence Video Communication Server17/7/202417/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting…
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.2)41%—Cisco Telepresence Video Communication Server16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an…
ModificadaAlta (7.7)0.66%—Cisco Telepresence Video Communication Server28/6/202317/6/2026
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway…
ModificadaMedia (6.5)0.91%—Cisco Telepresence Video Communication Server28/6/202317/6/2026
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling…
ModificadaMedia (5.9)1.1%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaMedia (6.5)1.9%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaMedia (6.5)0.98%—Cisco Telepresence Video Communication Server27/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaAlta (7.1)0.97%—Cisco Telepresence Video Communication Server27/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaMedia (6.5)0.96%—Cisco Telepresence Video Communication Server26/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaAlta (7.2)3.3%—Cisco Telepresence Video Communication Server6/4/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating…
ModificadaAlta (7.2)3.3%—Cisco Telepresence Video Communication Server6/4/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating…
ModificadaCrítica (9.8)1.9%—Fatek Communication Server Firmware15/10/202117/6/2026
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to remotely execute code.
ModificadaAlta (7.2)2.4%—Cisco ExpresswayCisco Telepresence Video Communication Server18/8/202117/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of…
ModificadaAlta (7.2)1.1%—Cisco ExpresswayCisco Telepresence Video Communication Server18/8/202117/6/2026
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of…
ModificadaMedia (6.5)1.4%—Cisco ExpresswayCisco Telepresence Video Communication Server18/11/202017/6/2026
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection…
ModificadaAlta (7.5)1.2%—Cisco ExpresswayCisco Telepresence Video Communication Server8/10/202017/6/2026
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of incoming SIP…
ModificadaAlta (7.2)2.6%—Cisco Telepresence Video Communication Server29/10/201916/6/2026
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
ModificadaMedia (6.1)0.80%—Cisco Telepresence Video Communication Server16/10/201917/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The…