Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.34% | — | Hallowelt Bluespice | 30/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context. | |
| Modificada | Alta (7.5) | 0.27% | — | Midnightblue Tetra\ | 19/10/2023 | 17/6/2026 | Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in a bit-by-bit fashion. | |
| Modificada | Alta (7.5) | 0.61% | — | Midnightblue Tetra\ | 19/10/2023 | 17/6/2026 | The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks. | |
| Modificada | Alta (8.1) | 0.34% | — | Midnightblue Tetra\ | 19/10/2023 | 17/6/2026 | Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can manipulate the view of these counters in a… | |
| Modificada | Media (5.9) | 0.27% | — | Midnightblue Tetra\ | 19/10/2023 | 17/6/2026 | A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero. | |
| Modificada | Alta (8.8) | 0.26% | — | Dublue Table OF Contents Plus | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <= 2302 versions. | |
| Modificada | Alta (7.8) | 0.17% | — | Nvidia Bluefield 1 FirmwareNvidia Bluefield 2 LTS FirmwareNvidia Bluefield 2 GA FirmwareNvidia Bluefield 3 GA Firmware | 12/9/2023 | 17/6/2026 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges. | |
| Modificada | Media (6.1) | 0.37% | — | Blindsidenetworks Bigbluebutton | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions. | |
| Analizada | Media (5.4) | 0.34% | — | Navblue N-ops & Crew | 1/9/2023 | 17/6/2026 | NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (8.8) | 0.62% | — | Jenkins Blue Ocean | 16/8/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job. | |
| Modificada | Baja (3.1) | 0.20% | — | Bluetensq | 3/8/2023 | 9/7/2026 | Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the BLE channel. It allows attackers to decrease or increase the intensity of the stimulator by hijacking the BLE communication. | |
| Modificada | Crítica (9.8) | 0.73% | — | Blueyonder Postgraas Server | 18/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is the function _create_pg_connection/create_postgres_db of the file postgraas_server/backends/postgres_cluster/postgres_cluster_driver.py of the component PostgreSQL Backend Handler. The manipulation… | |
| Modificada | Alta (8.1) | 0.35% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID… | |
| Modificada | Alta (8.1) | 0.36% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update… | |
| Modificada | Media (6.8) | 0.32% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real… | |
| Modificada | Media (6.5) | 0.47% | — | Bigbluebutton | 26/6/2023 | 17/6/2026 | BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the presentation should be downloaded. This URL… | |
| Modificada | Media (6.5) | 0.29% | — | Silabs Bluetooth LOW Energy Software Development KIT | 15/6/2023 | 17/6/2026 | A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. | |
| Modificada | Alta (7.8) | 0.60% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 14/6/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI. | |
| Modificada | Media (5.5) | 0.33% | — | Leap Blue Light Filter | 9/6/2023 | 17/6/2026 | An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files. | |
| Modificada | Alta (7.8) | 0.40% | — | Leap Blue Light Filter | 9/6/2023 | 17/6/2026 | An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. | |
| Modificada | Media (4.3) | 0.41% | — | Bluetooth Core Specification | 2/6/2023 | 17/6/2026 | Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC identifier, along with device capabilities… | |
| Modificada | Crítica (9.8) | 0.75% | — | Bluecms Project Bluecms | 30/5/2023 | 17/6/2026 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | |
| Modificada | Media (5.3) | 0.57% | — | Netapp Blue XP Connector | 26/5/2023 | 17/6/2026 | NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector. | |
| Modificada | Media (6.5) | 0.52% | — | Johnsoncontrols Openblue Enterprise Manager Data Collector | 18/5/2023 | 17/6/2026 | OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances. | |
| Modificada | Alta (7.5) | 1.1% | 💥 PoC | Johnsoncontrols Openblue Enterprise Manager Data Collector | 18/5/2023 | 17/6/2026 | Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances. |