Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.7% | — | Adobe Bridge | 20/8/2021 | 17/6/2026 | Adobe Bridge version 11.0.2 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction… | |
| Modificada | Alta (7.8) | 7.2% | — | Adobe Bridge | 20/8/2021 | 17/6/2026 | Adobe Bridge version 11.0.2 (and earlier) are affected by a Heap-based Buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Crítica (9.8) | 1.3% | — | Trezor Bridge | 26/7/2021 | 17/6/2026 | A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Media (4.9) | 0.94% | — | Matrix-appservice-bridge | 16/6/2021 | 17/6/2026 | Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it… | |
| Modificada | Alta (8.8) | 0.96% | — | Tracefinanacial Crestbridge | 10/6/2021 | 17/6/2026 | Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03. | |
| Modificada | Media (5.4) | 0.49% | — | Tracefinancial Crestbridge | 10/6/2021 | 17/6/2026 | Trace Financial Crest Bridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. | |
| Modificada | Alta (8.8) | 0.96% | — | Tracefinanacial Crestbridge | 10/6/2021 | 17/6/2026 | Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03. | |
| Modificada | Media (5.4) | 0.49% | — | Tracefinanacial Crestbridge | 10/6/2021 | 17/6/2026 | Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. | |
| Modificada | Alta (7.2) | 1.3% | — | Paloaltonetworks Bridgecrew Checkov | 10/6/2021 | 17/6/2026 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted. | |
| Modificada | Alta (8.8) | 1.2% | — | Siemens Siveillance Video Open Network Bridge | 22/4/2021 | 17/6/2026 | A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance Video Open Network Bridge (2020 R1), Siveillance Video Open Network Bridge (2019 R3), Siveillance Video Open Network Bridge (2019 R2), Siveillance Video Open Network… | |
| Modificada | Alta (7.2) | 1.3% | — | Paloaltonetworks Bridgecrew Checkov | 20/4/2021 | 17/6/2026 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted. | |
| Modificada | Media (5.5) | 0.71% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerability in the Genuine Software Service. A low-privileged attacker could leverage this vulnerability to achieve application denial-of-service in the context of the current user. Exploitation of this… | |
| Modificada | Alta (7.8) | 3.9% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires… | |
| Modificada | Alta (7.8) | 3.9% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this… | |
| Modificada | Alta (7.8) | 3.9% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue… | |
| Modificada | Alta (7.8) | 3.9% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue… | |
| Modificada | Baja (3.3) | 2.4% | — | Adobe Bridge | 15/4/2021 | 17/6/2026 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue… | |
| Modificada | Alta (7.8) | 0.23% | — | Tibco Messaging - Eclipse Mosquitto Distribution - Bridge | 14/4/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on… | |
| Modificada | Crítica (9.8) | 1.7% | — | Microfocus Operations Bridge Manager | 8/4/2021 | 17/6/2026 | Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Security Verify Bridge | 3/3/2021 | 17/6/2026 | IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618. | |
| Modificada | Media (5.9) | 0.81% | — | IBM Security Verify Bridge | 3/3/2021 | 17/6/2026 | IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617. | |
| Modificada | Alta (7.8) | 3.7% | — | Adobe Bridge | 25/2/2021 | 17/6/2026 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 3.7% | — | Adobe Bridge | 25/2/2021 | 17/6/2026 | Adobe Bridge version 11.0 (and earlier) is affected by an out-of-bounds write vulnerability when parsing TTF files that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.61% | — | Voiceye Wsactivebridgees Project Voiceye Wsactivebridges | 24/2/2021 | 17/6/2026 | VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improper bound checking parameter given by attack. It finally leads to a stack-based buffer overflow via access to crafted web page. |