Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 NEO Firmware14/11/201917/6/2026
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXXS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (8.8)1.5%—Jenkins Neoload16/10/201917/6/2026
Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
AnalizadaAlta (7.8)72%⚠ Explotación activa💥 ExploitGoogle AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+7311/10/201917/6/2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing…
ModificadaCrítica (9.8)2.2%—Dynamicpress Neosense13/9/201917/6/2026
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
ModificadaAlta (8.2)1.9%—Mediola NEO Server14/8/201917/6/2026
eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details. This is related to improper access control for addons configuration pages and a missing check in…
ModificadaAlta (8.1)2.7%💥 PoCGoogle AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaAlta (8.6)19%💥 ExploitVIMNeovim5/6/201917/6/2026
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
ModificadaMedia (5.5)0.68%—Hancom Office 2010Hancom Office 2014Hancom Office 2018Hancom Office NEO21/12/201817/6/2026
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.
ModificadaCrítica (10)1.9%—Neo4j Awesome Procedures ON Cyper20/12/201817/6/2026
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.
ModificadaMedia (6.1)1.0%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)1.5%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors.
ModificadaAlta (8.8)1.2%—NEO Debun POP15/11/201817/6/2026
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.
ModificadaCrítica (9.8)3.6%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.
ModificadaCrítica (9.8)3.6%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.
ModificadaCrítica (9.8)1.8%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.
ModificadaCrítica (9.8)1.7%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.
ModificadaCrítica (9.8)1.7%—NEO Debun ImapNEO Debun POP15/11/201817/6/2026
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.
ModificadaCrítica (9.8)1.9%—Neo4j16/10/201817/6/2026
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
ModificadaAlta (7.5)2.2%—Debian LinuxNeomutt17/7/201817/6/2026
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
ModificadaCrítica (9.8)3.7%—MuttNeomuttCanonical Ubuntu LinuxDebian Linux+617/7/201817/6/2026
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
ModificadaCrítica (9.8)2.5%—Debian LinuxNeomutt17/7/201817/6/2026
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
ModificadaCrítica (9.8)2.7%—Debian LinuxNeomutt17/7/201817/6/2026
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
ModificadaCrítica (9.8)4.1%—MuttNeomuttCanonical Ubuntu LinuxDebian Linux17/7/201817/6/2026
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
ModificadaCrítica (9.8)3.9%—MuttNeomuttCanonical Ubuntu LinuxDebian Linux17/7/201817/6/2026
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
ModificadaCrítica (9.8)5.0%—MuttNeomuttCanonical Ubuntu LinuxDebian Linux+617/7/201817/6/2026
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
Orbitaley — Vulnerabilidades