Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)0.64%—Cisco Telepresence Video Communication Server15/11/202417/6/2026
A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
AnalizadaAlta (7.4)0.91%—Cisco Telepresence Video Communication Server15/11/202417/6/2026
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device…
AnalizadaMedia (6.7)0.55%—Cisco Telepresence Video Communication Server2/10/202417/6/2026
A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have Administrator-level credentials with read-write…
AnalizadaMedia (4.7)0.38%—Cisco Telepresence Video Communication Server17/7/202417/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.2)41%💥 PoCCisco Telepresence Video Communication Server16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an…
ModificadaAlta (7.7)0.66%—Cisco Telepresence Video Communication Server28/6/202317/6/2026
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway…
ModificadaMedia (6.5)0.91%—Cisco Telepresence Video Communication Server28/6/202317/6/2026
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling…
ModificadaMedia (5.9)1.1%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaMedia (6.5)1.9%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaMedia (6.5)0.98%—Cisco Telepresence Video Communication Server27/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaAlta (7.1)0.97%—Cisco Telepresence Video Communication Server27/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaMedia (6.5)0.96%—Cisco Telepresence Video Communication Server26/5/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these…
ModificadaAlta (7.2)3.3%—Cisco Telepresence Video Communication Server6/4/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating…
ModificadaAlta (7.2)3.3%—Cisco Telepresence Video Communication Server6/4/202217/6/2026
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating…
ModificadaAlta (7.2)2.4%—Cisco ExpresswayCisco Telepresence Video Communication Server18/8/202117/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of…
ModificadaAlta (7.2)1.1%—Cisco ExpresswayCisco Telepresence Video Communication Server18/8/202117/6/2026
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of…
ModificadaMedia (6.5)1.4%—Cisco ExpresswayCisco Telepresence Video Communication Server18/11/202017/6/2026
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection…
ModificadaAlta (7.5)1.2%—Cisco ExpresswayCisco Telepresence Video Communication Server8/10/202017/6/2026
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of incoming SIP…
ModificadaAlta (7.2)2.6%—Cisco Telepresence Video Communication Server29/10/201916/6/2026
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
ModificadaMedia (6.1)0.80%—Cisco Telepresence Video Communication Server16/10/201917/6/2026
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The…
ModificadaMedia (5.3)1.5%—Cisco Telepresence Video Communication Server5/6/201917/6/2026
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An…
ModificadaAlta (8.6)4.6%—Cisco Telepresence Video Communication ServerCisco Unified Communications Manager IM AND Presence Service5/6/201917/6/2026
A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to…
ModificadaMedia (4.3)3.7%—Cisco Telepresence Video Communication Server3/5/201917/6/2026
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by…
ModificadaMedia (6.5)0.69%—Cisco Expressway SeriesCisco Telepresence Video Communication Server18/4/201917/6/2026
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient…
Orbitaley — Vulnerabilidades