Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.27% | — | UnifyAI | 7/1/2026 | 17/6/2026 | The Unify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'init' action in all versions up to, and including, 3.4.9. This makes it possible for unauthenticated attackers to delete specific plugin options via the 'unify_plugin_downgrade' parameter. | |
| Aplazada | Media (6.4) | 0.30% | — | UnifyAI | 3/10/2025 | 17/6/2026 | The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkout shortcode in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.55% | — | Cososys Endpoint ProtectorAIUnify AgentAI | 27/6/2024 | 17/6/2026 | The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain… | |
| Aplazada | Alta (7.2) | 0.78% | — | Netwrix Cososys UnifyAICososys Endpoint ProtectorAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. An attacker with administrative access to the Endpoint Protector or Unify server… | |
| Aplazada | Alta (7.2) | 0.78% | — | Netwrix Cososys UnifyAICososys Endpoint ProtectorAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector and Unify agent which allows an attacker with administrative access to the Endpoint Protector or Unify server to overwrite sensitive… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Netwrix Endpoint ProtectorAICososys UnifyAI | 27/6/2024 | 17/6/2026 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector and Unify server application which allows an unauthenticated remote attacker to send a malicious request, resulting in the ability to execute… | |
| Aplazada | Media (5.9) | 0.23% | — | Unify CP IP PhoneAI | 5/4/2024 | 17/6/2026 | In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash. | |
| Analizada | Media (4.3) | 0.45% | — | Unify Openscape Voice Trace Manager | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface. | |
| Analizada | Alta (8.8) | 1.2% | — | Unify Openscape Voice Trace Manager | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp. | |
| Analizada | Media (6.1) | 0.33% | — | Unify Openscape Voice Trace Manager | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request. | |
| Modificada | Crítica (9.8) | 0.70% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal. | |
| Modificada | Alta (8.8) | 0.92% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload. | |
| Modificada | Alta (7.5) | 1.0% | — | Unify Openscape Voice | 12/1/2024 | 17/6/2026 | A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents of arbitrary files in the local file system. An unauthenticated attacker might obtain sensitive files that allow for the compromise of the underlying… | |
| Modificada | Crítica (9.8) | 1.9% | — | Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller | 5/12/2023 | 17/6/2026 | An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain… | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as… | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120. | |
| Modificada | Alta (8.8) | 0.90% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589. | |
| Modificada | Alta (8.8) | 0.71% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of arbitrary files affecting the underlying… | |
| Modificada | Alta (8.8) | 0.81% | — | Atos Unify Openscape Common Management | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as… | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039. | |
| Modificada | Alta (8.8) | 0.57% | — | Atos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034. | |
| Modificada | Alta (7.5) | 0.47% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as… | |
| Modificada | Crítica (9.8) | 3.9% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users. | |
| Modificada | Alta (8.8) | 3.8% | — | Unify Session Border Controller | 4/10/2023 | 17/6/2026 | Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users. | |
| Modificada | Alta (8.8) | 0.42% | — | Silabs Unify Software Development KIT | 21/6/2023 | 17/6/2026 | Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. |