Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Hillrom Connex Central StationHillrom Connex Device Integration Suite Network Connectivity EngineHillrom Connex Integrated Wall SystemHillrom Connex Spot Monitor+5 | 11/6/2021 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior… | |
| Modificada | Alta (7.5) | 1.7% | — | Hillrom Connex Central StationHillrom Connex Device Integration Suite Network Connectivity EngineHillrom Connex Integrated Wall SystemHillrom Connex Spot Monitor+5 | 11/6/2021 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device… | |
| Modificada | Media (6.1) | 2.2% | — | Centreon Host-monitoring WidgetCentreon Tactical-overview WidgetCentreon Service-monitoring Widget | 27/5/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of… | |
| Modificada | Media (6.1) | 2.2% | — | Centreon Host-monitoring WidgetCentreon Tactical-overview WidgetCentreon Service-monitoring Widget | 27/5/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of… | |
| Modificada | Media (6.1) | 2.2% | — | Centreon Host-monitoring WidgetCentreon Tactical-overview WidgetCentreon Service-monitoring Widget | 27/5/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the… | |
| Modificada | Media (5) | 1.6% | — | Cisco Prime LAN Management SolutionCisco Security ManagerCisco Unified Operations ManagerCisco Unified Service Monitor | 12/9/2013 | 16/6/2026 | Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to cause a denial of service (memory consumption) via… | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Unified Operations ManagerCisco Unified Service Monitor | 10/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web framework in the unified-communications management implementation in Cisco Unified Operations Manager and Unified Service Monitor allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuh47574 and CSCuh95997. | |
| Modificada | Alta (7.6) | 7.2% | — | IBM Tivoli Netcool Application Service MonitorsIBM Tivoli Netcool System Service Monitors | 5/6/2013 | 16/6/2026 | Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transaction with a long table name that is not properly handled by a packet decoder. | |
| Modificada | Alta (7.6) | 3.0% | — | IBM Tivoli Netcool Application Service MonitorsIBM Tivoli Netcool System Service Monitors | 5/6/2013 | 16/6/2026 | Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or cause a denial of service via a long line in (1) hrfstable.idx, (2) hrdevice.idx, (3) hrstorage.idx,… | |
| Modificada | Alta (10) | 11% | — | Cisco Unified Service MonitorCiscoworks LAN Management SolutionCisco Unified Operations ManagerEMC Ionix ACM+2 | 19/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for… | |
| Modificada | Alta (10) | 6.0% | — | Ciscoworks Common ServicesCiscoworks LAN Management SolutionCisco QOS Policy ManagerCisco Security Manager+3 | 29/10/2010 | 16/6/2026 | Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352. | |
| Modificada | Alta (10) | 13% | — | Ciscoworks Common ServicesCiscoworks Health AND Utilization MonitorCiscoworks LAN Management SolutionCiscoworks QOS Policy Manager+6 | 21/5/2009 | 16/6/2026 | Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows… |