Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.45%—Cisco Spa500ds FirmwareCisco Spa500s FirmwareCisco Spa501g FirmwareCisco Spa502g Firmware+83/8/202317/6/2026
A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management…
ModificadaMedia (6.1)0.53%—Cisco Spa500ds FirmwareCisco Spa500s FirmwareCisco Spa501g FirmwareCisco Spa502g Firmware+83/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An…
ModificadaMedia (6.6)0.48%—Cisco Spa501g FirmwareCisco Spa502g FirmwareCisco Spa504g FirmwareCisco Spa508g Firmware+617/7/201917/6/2026
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device configuration interface. An attacker could exploit this vulnerability by accessing the…
ModificadaAlta (7.4)0.87%—Cisco Spa112 FirmwareCisco Spa525 FirmwareCisco Spa5x5 FirmwareCisco Spa500 Firmware+1025/2/201917/6/2026
A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could allow an unauthenticated, remote attacker to listen to or control some aspects of a Transport Level Security (TLS)-encrypted Session Initiation Protocol (SIP) conversation. The vulnerability is due to…