Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.63% | — | Cisco Hosted Collaboration SolutionCisco Unified Communications Domain Manager | 26/11/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to… | |
| Modificada | Alta (7.8) | 0.32% | — | Cisco Hosted Collaboration Solution | 6/7/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing… | |
| Modificada | Media (6.1) | 1.8% | — | Cisco Hosted Collaboration SolutionCisco Unified Communications Domain Manager | 15/8/2018 | 17/6/2026 | A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to improper validation of input that is passed to the affected software. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 6.4% | — | Cisco Emergency ResponderCisco FinesseCisco Hosted Collaboration SolutionCisco Mediasense+7 | 16/11/2017 | 17/6/2026 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration… | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa | Apache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+3 | 15/9/2017 | 17/6/2026 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads. | |
| Modificada | Media (4) | 0.95% | — | Cisco Hosted Collaboration Solution | 15/12/2015 | 17/6/2026 | Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Hosted Collaboration SolutionCisco Unified Communications Domain Manager | 30/10/2015 | 17/6/2026 | Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut67891. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 1/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Hosted Collaboration Solution | 10/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Hosted Collaboration Solution | 23/5/2015 | 17/6/2026 | The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786. | |
| Modificada | Media (6.8) | 1.3% | — | Cisco Hosted Collaboration Solution | 21/5/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596. | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Hosted Collaboration Solution | 19/2/2015 | 17/6/2026 | The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114. | |
| Modificada | Media (5) | 3.0% | — | Cisco Hosted Collaboration Solution | 19/3/2014 | 17/6/2026 | Memory leak in the GUI in the Impact server in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCub58999. | |
| Modificada | Media (5) | 3.0% | — | Cisco Hosted Collaboration Solution | 19/3/2014 | 17/6/2026 | The Java-based software in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (closing of TCP ports) via unspecified vectors, aka Bug IDs CSCug77633, CSCug77667, CSCug78266, CSCug82795, and CSCuh58643. | |
| Modificada | Media (5) | 1.2% | — | Cisco Prime Central FOR Hosted Collaboration Solution | 6/11/2013 | 16/6/2026 | The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313. | |
| Modificada | Media (5) | 1.8% | — | Cisco Prime Central FOR Hosted Collaboration Solution | 4/11/2013 | 16/6/2026 | The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345. | |
| Modificada | Media (4.3) | 0.28% | — | Cisco Prime Central FOR Hosted Collaboration Solution | 10/10/2013 | 16/6/2026 | The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230. | |
| Modificada | Alta (7.8) | 1.5% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 20/9/2013 | 16/6/2026 | The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 25/8/2013 | 16/6/2026 | Memory leak in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug ID CSCub59158. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 25/8/2013 | 16/6/2026 | Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port (1) 61615 or (2) 61616, aka Bug ID CSCtz90114. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 25/8/2013 | 16/6/2026 | Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Prime Central FOR Hosted Collaboration Solution Assurance | 25/8/2013 | 16/6/2026 | Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (disk consumption) via a flood of TCP packets to port 5400, leading to large error-log files, aka Bug ID CSCua42724. | |
| Modificada | Media (5) | 1.2% | — | Cisco Prime Central FOR Hosted Collaboration Solution | 26/6/2013 | 16/6/2026 | The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and files via a series of crafted requests, aka Bug ID CSCuh64574. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Prime Central FOR Hosted Collaboration Solution | 14/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798. | |
| Modificada | Media (5) | 1.2% | — | Cisco Hosted Collaboration Solution | 12/6/2013 | 16/6/2026 | Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on port 162, aka Bug ID CSCug85756. |