Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 API Manager AnalyticsWso2 Data Analytics Server+1116/10/202525/9/2026
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This…
ModificadaCrítica (9.8)0.88%—Sierrawireless Airlink Mobility Manager26/12/202217/6/2026
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
ModificadaMedia (4.8)3.8%—Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+1321/9/201717/6/2026
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
ModificadaMedia (5)1.2%—Mcafee Enterprise Mobility Manager22/8/201216/6/2026
The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
ModificadaMedia (5)1.2%—Mcafee Enterprise Mobility Manager22/8/201216/6/2026
About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information by visiting this page.
ModificadaMedia (4.3)0.93%—Mcafee Enterprise Mobility Manager22/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 might allow remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Connection variable.
ModificadaBaja (2.1)0.43%—Mcafee Enterprise Mobility Manager22/8/201216/6/2026
Login.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
ModificadaMedia (4.3)1.1%—Mcafee Enterprise Mobility ManagerMcafee Enterprise Mobility Manager Agent22/8/201216/6/2026
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administrator may wish to unlock, which allows remote attackers to cause a denial of service (excessive list size in the EMM…
ModificadaBaja (3.5)0.85%—Mcafee Enterprise Mobility ManagerMcafee Enterprise Mobility Manager Agent22/8/201216/6/2026
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attackers to discover user passwords by spoofing the EMM server, as demonstrated by a password entered on…
ModificadaAlta (10)5.1%—Cisco Emergency ResponderCisco Mobility ManagerCisco Unified Communications ManagerCisco Unified Presence4/4/200816/6/2026
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which…
ModificadaBaja (2.1)0.31%—Globetrotter Mobility Manager29/1/200716/6/2026
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as for passwords, by shoulder surfing or grabbing periodic screenshots.