Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 7.6% | — | Audiocodes 420hd IP Phone Firmware | 1/4/2019 | 17/6/2026 | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via… | |
| Modificada | Alta (8.8) | 68% | — | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution. | |
| Modificada | Media (4.8) | 0.77% | — | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS. | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Unified IP Phone FirmwareCisco IP Phone Firmware | 7/6/2018 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco IP Phone Firmware | 7/6/2018 | 17/6/2026 | A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS)… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Small Business IP Phone Firmware | 19/10/2017 | 17/6/2026 | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the… | |
| Modificada | Media (5) | 5.2% | — | Yealink Voip Phone Firmware | 16/7/2014 | 17/6/2026 | CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet. | |
| Modificada | Media (4.3) | 1.9% | — | Yealink Voip Phone FirmwareYealink Voip Phone | 16/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet. | |
| Modificada | Media (6.6) | 0.28% | — | Cisco Unified IP Phone FirmwareCisco Unified IP Phone 8961Cisco Unified IP Phone 9951Cisco Unified IP Phone 9971 | 13/11/2013 | 17/6/2026 | The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382. | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco Unified IP Phone 8945Cisco Unified IP Phone Firmware | 29/8/2013 | 16/6/2026 | The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+14 | 13/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,… | |
| Modificada | Media (4.6) | 0.41% | — | Cisco Unified IP PhoneCisco Unified IP Phone Firmware | 3/5/2012 | 16/6/2026 | Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237. | |
| Modificada | Media (5) | 1.1% | — | Cisco Small Business IP Phone FirmwareCisco Small Business IP Phone | 2/5/2012 | 16/6/2026 | Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768. | |
| Modificada | Baja (3.3) | 0.80% | — | Snom Voip Phone Firmware | 15/6/2010 | 16/6/2026 | Unspecified vulnerability in the web interface in snom VoIP Phone firmware 8 before 8.2.35 allows remote attackers to bypass intended restrictions and modify user credentials via unknown vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.2) | 0.34% | — | Cisco Unified IP Phone Firmware 7906gCisco Unified IP Phone Firmware 7911gCisco Unified IP Phone Firmware 7941gCisco Unified IP Phone Firmware 7961g+2 | 22/2/2007 | 16/6/2026 | The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors. NOTE: this issue can be leveraged remotely via CVE-2007-1063. | |
| Modificada | Alta (10) | 3.4% | — | Cisco Unified IP Phone Firmware 7906gCisco Unified IP Phone Firmware 7911gCisco Unified IP Phone Firmware 7941gCisco Unified IP Phone Firmware 7961g+2 | 22/2/2007 | 16/6/2026 | The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device. |