Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (5.4) | 0.77% | — | Cisco Unified Customer Voice Portal | 22/7/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input validation of a parameter that is used by the web-based… | |
| Modificada | Media (6.8) | 0.93% | — | Cisco Unified Customer Voice Portal | 23/9/2020 | 17/6/2026 | A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application. The vulnerability is… | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Unified Customer Voice Portal | 2/7/2020 | 17/6/2026 | A vulnerability in the Java Remote Method Invocation (RMI) interface of Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because certain RMI listeners are not properly authenticated. An attacker… | |
| Modificada | Alta (8.6) | 2.3% | — | Cisco Unified Customer Voice Portal | 22/2/2018 | 17/6/2026 | A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper… | |
| Modificada | Alta (8.6) | 2.3% | — | Cisco Unified Customer Voice Portal | 18/1/2018 | 17/6/2026 | A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the… | |
| Modificada | Alta (8.8) | 2.2% | — | Cisco Unified Customer Voice Portal | 21/9/2017 | 17/6/2026 | A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker… | |
| Modificada | Media (6.8) | 0.71% | — | Cisco Unified Customer Voice Portal | 17/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Unified Customer Voice Portal | 19/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711, CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCuh61731, and CSCuh61733. | |
| Modificada | Alta (7.8) | 1.6% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369. | |
| Modificada | Alta (7.8) | 1.5% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372. | |
| Modificada | Alta (7.8) | 1.2% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379. | |
| Modificada | Alta (10) | 3.4% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to execute arbitrary code via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38384. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unified Customer Voice Portal | 9/5/2013 | 16/6/2026 | The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148. | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+6 | 30/9/2010 | 16/6/2026 | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked… | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+9 | 21/9/2010 | 16/6/2026 | The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+11 | 8/9/2010 | 16/6/2026 | The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelVmware ESXAvaya Aura Communication ManagerAvaya Aura Presence Services+5 | 8/9/2010 | 16/6/2026 | Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+14 | 16/11/2009 | 16/6/2026 | The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | |
| Modificada | Alta (9) | 3.0% | — | Cisco Unified Customer Voice Portal | 22/5/2008 | 16/6/2026 | Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser account. |