Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Itsourcecode Online Cellphone SystemAI | 5/4/2026 | 24/7/2026 | A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is… | |
| Modificada | Alta (8.8) | 1.7% | — | 3CX Phone System FirmwareDebian Linux | 7/6/2022 | 17/6/2026 | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling. | |
| Modificada | Alta (8.8) | 1.7% | — | 3CX Phone System FirmwareDebian Linux | 7/6/2022 | 17/6/2026 | PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used in conjunction with sudo. | |
| Modificada | Alta (7.5) | 10% | — | Jivesoftware JivePascom Cloud Phone System | 18/3/2022 | 17/6/2026 | An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394. | |
| Modificada | Crítica (9.8) | 21% | — | Pascom Cloud Phone SystemIgniterealtime Openfire | 18/3/2022 | 17/6/2026 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. | |
| Modificada | Crítica (9.8) | 6.0% | — | Pascom Cloud Phone System | 18/3/2022 | 17/6/2026 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters. | |
| Modificada | Media (5) | 1.1% | — | 3CX Phone System | 3/8/2009 | 16/6/2026 | login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote attackers to gain sensitive information via unspecified vectors that reveal the installation path. | |
| Modificada | Alta (7.8) | 1.2% | — | 3CX Phone System | 3/8/2009 | 16/6/2026 | 3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demonstrated by vulnerability scans from Nessus or SAINT. | |
| Modificada | Media (4.3) | 1.1% | — | 3CX Phone System | 3/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition 6.1793 and 6.0.806.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fName and (2) fPassword parameters. |