Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.86% | — | Blackberry Workspaces | 9/8/2017 | 17/6/2026 | An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server. | |
| Modificada | Media (5.4) | 1.5% | 💥 PoC | Blackcat-cms Blackcat CMS | 17/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php. | |
| Modificada | Media (6.1) | 0.85% | — | Blackberry Enterprise ServiceBlackberry Unified Endpoint Manager | 10/5/2017 | 17/6/2026 | A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target… | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Blackberry Enterprise Service | 13/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp. | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Blackberry Enterprise Service | 13/4/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3)… | |
| Modificada | Alta (7.5) | 1.4% | — | Blackberry Good Control Server | 3/3/2017 | 17/6/2026 | An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files… | |
| Modificada | Media (6.1) | 0.95% | — | Blackberry Appliance-xBlackberry Workspaces Vapp | 13/1/2017 | 17/6/2026 | A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious… | |
| Modificada | Alta (8.1) | 2.1% | — | Blackberry Enterprise Service | 13/1/2017 | 17/6/2026 | An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domain credentials of an administrator or user account by sniffing traffic between the two elements during a login attempt. | |
| Modificada | Alta (8.2) | 1.9% | — | Blackberry Enterprise Service | 13/1/2017 | 17/6/2026 | A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to the BES by gaining access to specific information about a device that was… | |
| Modificada | Media (6.6) | 2.9% | — | Blackberry Good Enterprise Mobility Server | 16/12/2016 | 17/6/2026 | A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell. | |
| Modificada | Media (6.5) | 1.2% | — | Blackbox Alertwerks Servsensor Junior FirmwareBlackbox Alertwerks Servsensor Contact FirmwareBlackbox Alertwerks Servsensor Firmware | 30/5/2016 | 17/6/2026 | Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact with firmware before SP473 allow remote authenticated users to discover administrator and user… | |
| Modificada | Media (6.1) | 1.0% | — | Blackberry Enterprise Server | 22/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 1.0% | — | Blackberry Enterprise Server | 22/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917. | |
| Modificada | Media (6.1) | 1.0% | — | Blackberry Enterprise Server | 22/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1918. | |
| Modificada | Media (5.4) | 0.80% | — | Blackberry Enterprise Server | 22/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT… | |
| Modificada | Alta (9.3) | 2.0% | — | Honeywell Midas FirmwareHoneywell Midas Black Firmware | 21/12/2015 | 17/6/2026 | Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network. | |
| Modificada | Alta (8.6) | 3.6% | — | Honeywell Midas Black FirmwareHoneywell Midas Firmware | 21/12/2015 | 17/6/2026 | Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Blackberry Enterprise Server | 19/11/2015 | 17/6/2026 | The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue. | |
| Modificada | Alta (7.5) | 2.3% | — | Nintex K2 BlackpearlNintex K2 FOR SharepointNintex K2 Smartforms | 21/10/2015 | 17/6/2026 | SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter. | |
| Modificada | Media (6.8) | 4.4% | — | Blackberry Link | 20/7/2015 | 17/6/2026 | mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file. | |
| Modificada | Media (4.8) | 0.73% | — | Blackcat-cms Blackcat CMS | 14/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php. | |
| Modificada | Media (4.3) | 1.0% | — | Plainblack Webgui | 9/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field. | |
| Modificada | Media (4.3) | 0.99% | — | Blackberry WorldBlackberry OS | 25/10/2014 | 17/6/2026 | The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a… | |
| Modificada | Media (5.4) | 0.27% | — | Timelessblack Timeless Black | 16/10/2014 | 17/6/2026 | The Timeless Black (aka com.apptive.android.apps.timeless) application 2.10.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.0% | — | Blackcat-cms Blackcat CMS | 12/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. |