Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Sendquick EnteraAI | 14/3/2025 | 17/6/2026 | SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter. | |
| Aplazada | Media (5.3) | 0.39% | — | TalenteraAI | 9/12/2024 | 17/6/2026 | A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.2) | 1.0% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective. | |
| Modificada | Alta (7.5) | 1.8% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. | |
| Modificada | Media (5.4) | 1.1% | — | Enterasys C5Enterasys G3Enterasys K10Enterasys K6+5 | 23/1/2014 | 17/6/2026 | The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive… | |
| Modificada | Alta (10) | 77% | — | Enterasys Netsight | 25/10/2012 | 16/6/2026 | Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514. | |
| Modificada | Alta (7.5) | 1.2% | — | EMC Centera Universal Access | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field. | |
| Modificada | Alta (7.8) | 1.9% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field. | |
| Modificada | Alta (7.5) | 4.0% | — | Enterasys Netsight ConsoleEnterasys Netsight Inventory Manager | 27/4/2007 | 16/6/2026 | Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names. | |
| Modificada | Media (5) | 0.99% | — | Enterasys Vertical Horizon-2402s | 16/6/2005 | 16/6/2026 | Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry. | |
| Modificada | Alta (7.5) | 1.3% | — | Enterasys Vertical Horizon-2402s | 16/6/2005 | 16/6/2026 | Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Enterasys Xsr-1805Enterasys Xsr-1850Enterasys Xsr-3000 | 6/8/2004 | 16/6/2026 | Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set. | |
| Modificada | Media (5) | 7.0% | — | Enterasys Smartswitch Ssr8000 | 2/4/2003 | 16/6/2026 | The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078. | |
| Modificada | Alta (7.5) | 4.4% | — | Cisco Catalyst 6000 Intrusion Detection System ModuleCisco Secure Intrusion Detection SystemISS Realsecure Network SensorISS Realsecure Server Sensor+2 | 30/10/2001 | 16/6/2026 | Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for… |