Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (8.7)0.67%—Arteco WEB Client DVR NVRAI6/1/202617/6/2026
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.
AplazadaMedia (5.4)0.28%—AVE System WEB ClientAI27/2/202517/6/2026
AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.
AplazadaAlta (7.3)0.41%—Instinct UI WEB ClientAI2/4/202417/6/2026
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
ModificadaAlta (8.1)1.1%—Johnsoncontrols Victor WEB ClientTyco C-cure WEB Client8/10/202017/6/2026
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
ModificadaAlta (7.5)1.9%—Atos Unify Openscape UC WEB Client21/2/202017/6/2026
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and…
ModificadaMedia (6.1)0.65%—Atos Unify Openscape UC WEB Client21/2/202017/6/2026
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
ModificadaAlta (7.5)1.2%—Hyland Saperion WEB Client13/2/201817/6/2026
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
ModificadaCrítica (9.8)3.8%—Hyland Saperion WEB Client13/2/201817/6/2026
Remote Code Execution in Saperion Web Client version 7.5.2 83166.
ModificadaAlta (7.3)2.4%—Panasonic Video Insight WEB Client13/2/201717/6/2026
An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.
ModificadaAlta (8)0.83%—HP Service ManagerHP Service Manager MobilityHP Service Manager ServerHP Service Manager Service Request Catalog+219/6/201617/6/2026
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request…
ModificadaMedia (5)2.6%—Clorius Controls A/S Java WEB Client17/1/201517/6/2026
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
ModificadaMedia (6.8)0.56%—IBM Sametime Proxy Server AND WEB Client26/5/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the Web player in IBM Sametime Proxy Server and Web Client 9.0 through 9.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaMedia (4.3)2.6%—HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier29/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.2)0.84%—HP Service ManagerHP Service Manager WEB ClientHP Service Manager WEB Tier29/12/201317/6/2026
Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaMedia (5)1.4%—Hitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal5/11/200716/6/2026
Unspecified vulnerability in the Groupmax Collaboration - Schedule component in Hitachi Groupmax Collaboration Portal 07-30 through 07-30-/F and 07-32 through 07-32-/C, uCosminexus Collaboration Portal 06-30 through 06-30-/F and 06-32 through 06-32-/C, and Groupmax Collaboration Web Client - Mail/Schedule 07-30…
ModificadaBaja (3.5)0.86%—Hitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal8/8/200716/6/2026
Hitachi Groupmax Collaboration - Schedule, as used in Groupmax Collaboration Portal 07-32 through 07-32-/B, uCosminexus Collaboration Portal 06-32 through 06-32-/B, and Groupmax Collaboration Web Client - Mail/Schedule 07-32 through 07-32-/A, can assign schedule data to the wrong user under unspecified conditions,…
ModificadaMedia (4.3)1.2%—Hitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal5/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus…
ModificadaMedia (6.8)1.2%—Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB ClientHitachi Ucosminexus Collaboration Portal+131/3/200716/6/2026
SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute…
ModificadaMedia (6.8)1.4%—Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client13/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts" via unknown vectors (aka HS06-014-01).
ModificadaMedia (4.3)1.4%—Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client17/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule…
ModificadaAlta (7.8)2.0%—Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client17/12/200516/6/2026
Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the…
ModificadaMedia (5)59%—Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+1523/12/200416/6/2026
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number…
ModificadaMedia (5)34%—Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+1418/8/200416/6/2026
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by…
ModificadaAlta (7.5)2.1%—Ganglia PHP RRD WEB Client31/12/200216/6/2026
graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.