Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.67% | — | BluezCanonical Ubuntu LinuxDebian Linux | 2/9/2022 | 17/6/2026 | BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c. | |
| Modificada | Alta (8.8) | 0.70% | — | BluezCanonical Ubuntu LinuxDebian Linux | 2/9/2022 | 17/6/2026 | BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len. | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.47% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service. | |
| Modificada | Media (6.5) | 0.37% | — | Realtek Bluetooth Mesh Software Development KIT | 30/8/2022 | 17/6/2026 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service. | |
| Modificada | Media (5.3) | 0.78% | — | Ssctech Blue Prism Enterprise | 26/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the UpdateOfflineHelpData administrative function.… | |
| Modificada | Alta (8.1) | 1.0% | — | Ssctech Blue Prism Enterprise | 26/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a… | |
| Modificada | Alta (8.8) | 2.0% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of… | |
| Modificada | Media (5.3) | 0.78% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function.… | |
| Modificada | Baja (3.1) | 0.69% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is… | |
| Modificada | Media (5.3) | 0.86% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function.… | |
| Modificada | Alta (7.1) | 0.94% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the… | |
| Modificada | Crítica (9.8) | 15% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | |
| Modificada | Crítica (9.8) | 0.88% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | |
| Modificada | Crítica (9.8) | 0.90% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | |
| Modificada | Media (5.5) | 0.19% | — | Intel Team Blue | 18/8/2022 | 17/6/2026 | Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 0.45% | — | Hallowelt Bluespice | 22/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL. | |
| Modificada | Media (6.1) | 0.45% | — | Hallowelt Bluespice | 22/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL. | |
| Modificada | Media (6.1) | 0.77% | — | Bigbluebutton | 27/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript), the script gets executed. Additionally… | |
| Modificada | Media (5.4) | 1.3% | — | Bigbluebutton | 27/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has… | |
| Modificada | Media (5.3) | 0.69% | — | Bigbluebutton Greenlight | 27/6/2022 | 17/6/2026 | Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6. | |
| Modificada | Media (5.4) | 0.45% | — | Bigbluebutton | 24/6/2022 | 17/6/2026 | BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when… | |
| Modificada | Media (5.4) | 0.84% | — | Bigbluebutton Greenlight | 2/6/2022 | 17/6/2026 | BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously. | |
| Modificada | Media (4.3) | 0.87% | — | Bigbluebutton | 2/6/2022 | 17/6/2026 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The… |