Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.12%—Navayan SubscribeAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amol Nirmala Waman Navayan Subscribe navayan-subscribe allows Stored XSS.This issue affects Navayan Subscribe: from n/a through <= 1.13.
AnalizadaMedia (6.5)0.37%—Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+212/6/202517/6/2026
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
AnalizadaCrítica (9.8)0.43%—Avaya Call Management System10/6/202517/6/2026
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
ModificadaMedia (6.1)0.28%—Avaya Spaces11/2/202517/6/2026
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.
AnalizadaMedia (5.4)0.32%—Avaya Spaces11/2/202517/6/2026
A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.
AplazadaCrítica (9.3)1.2%—Amol Nirmala Waman Navayan Navayan CSV ExportAI16/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.
ModificadaMedia (4.4)0.15%—Avaya Aura System Manager8/8/202417/6/2026
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
AnalizadaMedia (6.7)0.19%—Avaya Aura System Manager8/8/202417/6/2026
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
AnalizadaCrítica (9.8)0.78%—Avaya IP Office25/6/202417/6/2026
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
ModificadaCrítica (9.8)0.59%—Avaya IP Office25/6/202417/6/2026
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.
ModificadaMedia (4.3)0.34%—Avaya Aura Experience Portal17/1/202417/6/2026
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer…
ModificadaCrítica (9.8)3.9%—Avaya Aura Device Services19/7/202317/6/2026
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
ModificadaMedia (6.8)0.57%—Avaya Call Management System18/7/202317/6/2026
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software…
ModificadaMedia (6.1)0.34%—Avaya IX Workforce Engagement30/5/202317/6/2026
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
ModificadaMedia (6.5)0.47%—Avaya IX Workforce Engagement30/5/202317/6/2026
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
ModificadaMedia (5.3)0.45%—Avaya IX Workforce Engagement30/5/202317/6/2026
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
ModificadaCrítica (9.1)1.1%—Avaya Scopia Pathfinder 10 PTS FirmwareAvaya Scopia Pathfinder 20 PTS Firmware3/11/202217/6/2026
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
ModificadaMedia (6.7)0.20%—Avaya Aura Communication Manager12/10/202217/6/2026
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
ModificadaMedia (6.7)0.22%—Avaya Aura Application Enablement Services6/10/202217/6/2026
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and…
ModificadaAlta (7.8)0.26%—Avaya IP Office2/9/202217/6/2026
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.
ModificadaAlta (7.8)0.78%—Avaya Aura Device Services25/6/202117/6/2026
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
ModificadaMedia (5.4)0.34%—Avaya Aura Experience Portal24/6/202117/6/2026
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
ModificadaMedia (6.1)0.38%—Avaya Aura Experience Portal24/6/202117/6/2026
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
ModificadaAlta (7.8)0.64%—Avaya Aura Appliance Virtualization Platform24/6/202117/6/2026
A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.
ModificadaMedia (5.5)0.70%—Avaya Aura Appliance Virtualization Platform24/6/202117/6/2026
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a…