Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Blueglass Jobs FOR Wordpress3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.10.2 versions.
ModificadaMedia (4.8)0.37%—Digitalblue Click TO Call OR Chat Buttons25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions.
ModificadaMedia (5.4)0.39%—Blueglass Jobs FOR Wordpress23/4/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.
ModificadaCrítica (9.8)1.0%—Iss-oberlausitz Bluepage CMS3/4/202317/6/2026
BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.
ModificadaCrítica (9.8)1.0%—Iss-oberlausitz Bluepage CMS3/4/202317/6/2026
BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.
ModificadaCrítica (9.8)0.85%—Node-bluetooth Project Node-bluetooth9/3/202317/6/2026
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
ModificadaCrítica (9.8)0.66%—Node-bluetooth-serial-port Project Node-bluetooth-serial-port9/3/202317/6/2026
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
AnalizadaMedia (5.4)0.39%—Blueastral Page Builder\21/2/202317/6/2026
The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write…
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability…
ModificadaAlta (8.8)0.74%—Bestechnic Bluetooth Mesh Software Development KIT1/2/202317/6/2026
In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU.
ModificadaAlta (7.5)0.95%—Bluecatnetworks Device Registration Portal15/1/202317/6/2026
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are no longer supported. There is no…
ModificadaMedia (5.4)0.57%—Dublue Table OF Contents Plus9/1/202317/6/2026
The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaAlta (8.6)0.86%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
ModificadaMedia (6.5)0.49%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
ModificadaMedia (5.4)0.68%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+819/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
ModificadaMedia (5.4)0.64%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
ModificadaAlta (7.5)0.77%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+1019/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
ModificadaAlta (7.5)0.60%—Bigbluebutton17/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker to subscribe to viewers' webcams, even when the lock setting is…
ModificadaMedia (4.3)0.46%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker…
ModificadaMedia (5.7)0.58%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be…
ModificadaBaja (3.1)0.44%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This…
ModificadaBaja (2.7)0.69%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other users. Moderators should only be able to set none as the status…
ModificadaMedia (4.3)0.29%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the remaining registered users from the same…
ModificadaMedia (4.3)0.38%—Bigbluebutton16/12/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim…
Orbitaley — Vulnerabilidades