Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.2% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by… | |
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.5) | 0.69% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.4) | 1.2% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.6% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Crítica (9.8) | 1.9% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the PolicyAuthority/Common/FolderControl.jsp file via the unqID parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 1.3% | — | Quest Policy Authority FOR Unified Communications | 11/1/2021 | 17/6/2026 | Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the initFile.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |