Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | Samsung Galaxy J7 NEO Firmware | 14/11/2019 | 17/6/2026 | The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXXS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app… | |
| Modificada | Alta (8.8) | 1.5% | — | Jenkins Neoload | 16/10/2019 | 17/6/2026 | Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa💥 Exploit | Google AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+73 | 11/10/2019 | 17/6/2026 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing… | |
| Modificada | Crítica (9.8) | 2.2% | — | Dynamicpress Neosense | 13/9/2019 | 17/6/2026 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | |
| Modificada | Alta (8.2) | 1.9% | — | Mediola NEO Server | 14/8/2019 | 17/6/2026 | eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details. This is related to improper access control for addons configuration pages and a missing check in… | |
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Alta (8.6) | 19% | 💥 Exploit | VIMNeovim | 5/6/2019 | 17/6/2026 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | |
| Modificada | Media (5.5) | 0.68% | — | Hancom Office 2010Hancom Office 2014Hancom Office 2018Hancom Office NEO | 21/12/2018 | 17/6/2026 | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions. | |
| Modificada | Crítica (10) | 1.9% | — | Neo4j Awesome Procedures ON Cyper | 20/12/2018 | 17/6/2026 | neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c. | |
| Modificada | Media (6.1) | 1.0% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.2% | — | NEO Debun POP | 15/11/2018 | 17/6/2026 | SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search. | |
| Modificada | Crítica (9.8) | 3.6% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data. | |
| Modificada | Crítica (9.8) | 3.6% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data. | |
| Modificada | Crítica (9.8) | 1.8% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.7% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration. | |
| Modificada | Crítica (9.8) | 1.7% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration. | |
| Modificada | Crítica (9.8) | 1.9% | — | Neo4j | 16/10/2018 | 17/6/2026 | Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password. | |
| Modificada | Alta (7.5) | 2.2% | — | Debian LinuxNeomutt | 17/7/2018 | 17/6/2026 | An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames. | |
| Modificada | Crítica (9.8) | 3.7% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux+6 | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character. | |
| Modificada | Crítica (9.8) | 2.5% | — | Debian LinuxNeomutt | 17/7/2018 | 17/6/2026 | An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. | |
| Modificada | Crítica (9.8) | 2.7% | — | Debian LinuxNeomutt | 17/7/2018 | 17/6/2026 | An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage. | |
| Modificada | Crítica (9.8) | 4.1% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data. | |
| Modificada | Crítica (9.8) | 3.9% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field. | |
| Modificada | Crítica (9.8) | 5.0% | — | MuttNeomuttCanonical Ubuntu LinuxDebian Linux+6 | 17/7/2018 | 17/6/2026 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription. |