Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Blueglass Jobs FOR Wordpress | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.10.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Digitalblue Click TO Call OR Chat Buttons | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Blueglass Jobs FOR Wordpress | 23/4/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Iss-oberlausitz Bluepage CMS | 3/4/2023 | 17/6/2026 | BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload. | |
| Modificada | Crítica (9.8) | 1.0% | — | Iss-oberlausitz Bluepage CMS | 3/4/2023 | 17/6/2026 | BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload. | |
| Modificada | Crítica (9.8) | 0.85% | — | Node-bluetooth Project Node-bluetooth | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Modificada | Crítica (9.8) | 0.66% | — | Node-bluetooth-serial-port Project Node-bluetooth-serial-port | 9/3/2023 | 17/6/2026 | All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. | |
| Analizada | Media (5.4) | 0.39% | — | Blueastral Page Builder\ | 21/2/2023 | 17/6/2026 | The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write… | |
| Modificada | Alta (8.8) | 0.78% | — | Infineon Cypress Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability… | |
| Modificada | Alta (8.8) | 0.74% | — | Bestechnic Bluetooth Mesh Software Development KIT | 1/2/2023 | 17/6/2026 | In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU. | |
| Modificada | Alta (7.5) | 0.95% | — | Bluecatnetworks Device Registration Portal | 15/1/2023 | 17/6/2026 | BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are no longer supported. There is no… | |
| Modificada | Media (5.4) | 0.57% | — | Dublue Table OF Contents Plus | 9/1/2023 | 17/6/2026 | The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Alta (8.6) | 0.86% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages. | |
| Modificada | Media (6.5) | 0.49% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values. | |
| Modificada | Media (5.4) | 0.68% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+8 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete. | |
| Modificada | Media (5.4) | 0.64% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing. | |
| Modificada | Alta (7.5) | 0.77% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+10 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero. | |
| Modificada | Alta (7.5) | 0.60% | — | Bigbluebutton | 17/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker to subscribe to viewers' webcams, even when the lock setting is… | |
| Modificada | Media (4.3) | 0.46% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker… | |
| Modificada | Media (5.7) | 0.58% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be… | |
| Modificada | Baja (3.1) | 0.44% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This… | |
| Modificada | Baja (2.7) | 0.69% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other users. Moderators should only be able to set none as the status… | |
| Modificada | Media (4.3) | 0.29% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the remaining registered users from the same… | |
| Modificada | Media (4.3) | 0.38% | — | Bigbluebutton | 16/12/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim… |