Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Cisco SPA 301 1 Line IP PhoneCisco SPA 303 3 Line IP PhoneCisco SPA 501g 8-line IP PhoneCisco SPA 502g 1-line IP Phone+12 | 9/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582. | |
| Modificada | Media (6.9) | 0.37% | — | Cisco SPA 301 1 Line IP PhoneCisco SPA 303 3 Line IP PhoneCisco SPA 501g 8-line IP PhoneCisco SPA 502g 1-line IP Phone+12 | 9/7/2014 | 17/6/2026 | The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435. | |
| Modificada | Media (4.3) | 1.5% | — | Linksys Spa941 | 12/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message. | |
| Modificada | Alta (7.8) | 9.4% | — | Linksys Spa941 | 25/4/2007 | 16/6/2026 | The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request. |