Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.67%—BluezCanonical Ubuntu LinuxDebian Linux2/9/202217/6/2026
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
ModificadaAlta (8.8)0.70%—BluezCanonical Ubuntu LinuxDebian Linux2/9/202217/6/2026
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.47%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.
ModificadaMedia (6.5)0.37%—Realtek Bluetooth Mesh Software Development KIT30/8/202217/6/2026
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service.
ModificadaMedia (5.3)0.78%—Ssctech Blue Prism Enterprise26/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the UpdateOfflineHelpData administrative function.…
ModificadaAlta (8.1)1.0%—Ssctech Blue Prism Enterprise26/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a…
ModificadaAlta (8.8)2.0%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of…
ModificadaMedia (5.3)0.78%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function.…
ModificadaBaja (3.1)0.69%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is…
ModificadaMedia (5.3)0.86%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function.…
ModificadaAlta (7.1)0.94%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the…
ModificadaCrítica (9.8)15%—Bluecms Project Bluecms23/8/202217/6/2026
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
ModificadaCrítica (9.8)0.88%—Bluecms Project Bluecms23/8/202217/6/2026
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
ModificadaCrítica (9.8)0.90%—Bluecms Project Bluecms23/8/202217/6/2026
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
ModificadaMedia (5.5)0.19%—Intel Team Blue18/8/202217/6/2026
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.1)0.45%—Hallowelt Bluespice22/7/202217/6/2026
Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.
ModificadaMedia (6.1)0.45%—Hallowelt Bluespice22/7/202217/6/2026
Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.
ModificadaMedia (6.1)0.77%—Bigbluebutton27/6/202217/6/2026
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript), the script gets executed. Additionally…
ModificadaMedia (5.4)1.3%—Bigbluebutton27/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has…
ModificadaMedia (5.3)0.69%—Bigbluebutton Greenlight27/6/202217/6/2026
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.
ModificadaMedia (5.4)0.45%—Bigbluebutton24/6/202217/6/2026
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when…
ModificadaMedia (5.4)0.84%—Bigbluebutton Greenlight2/6/202217/6/2026
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.
ModificadaMedia (4.3)0.87%—Bigbluebutton2/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The…