Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Emerson Controlwave Micro Firmware | 7/3/2018 | 17/6/2026 | A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based buffer overflow vulnerability caused by sending crafted packets on Port 20547 could force the PLC… | |
| Modificada | Alta (8.8) | 5.0% | — | Adobe Shockwave Player | 19/2/2018 | 16/6/2026 | Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759. | |
| Modificada | Alta (8.3) | 11% | — | HP Aruba Airwave Glass | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found. | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Trustwave Secure WEB Gateway | 31/12/2017 | 17/6/2026 | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI. | |
| Modificada | Crítica (9.8) | 8.8% | — | Adobe Shockwave | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Shockwave 12.2.9.199 and earlier. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 2.2% | 💥 Exploit | Blackwave Dive Assistant | 12/9/2017 | 17/6/2026 | XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file. | |
| Modificada | Alta (7) | 0.29% | — | Waves Maxxaudio | 26/7/2017 | 17/6/2026 | Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. | |
| Modificada | Crítica (9.8) | 6.9% | — | Adobe Shockwave Player | 20/6/2017 | 17/6/2026 | Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.2% | — | Grandstream Wave | 21/4/2017 | 17/6/2026 | The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application. | |
| Modificada | Media (5.9) | 0.96% | — | Grandstream Wave | 21/4/2017 | 17/6/2026 | The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate. | |
| Modificada | Alta (8.1) | 1.7% | — | Grandstream Wave | 21/4/2017 | 17/6/2026 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by… | |
| Modificada | Crítica (9.8) | 1.3% | — | Dragonwavex Horizon Wireless Radio Firmware | 6/4/2017 | 17/6/2026 | DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions… | |
| Modificada | Alta (7.8) | 3.0% | — | Adobe Shockwave Player | 14/3/2017 | 17/6/2026 | Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege. | |
| Modificada | Alta (10) | 3.8% | — | Adobe Shockwave Player | 28/10/2015 | 17/6/2026 | Adobe Shockwave Player before 12.2.1.171 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Alta (10) | 5.6% | — | Adobe Shockwave Player | 9/9/2015 | 17/6/2026 | Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680. | |
| Modificada | Alta (10) | 5.1% | — | Adobe Shockwave Player | 9/9/2015 | 17/6/2026 | Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681. | |
| Modificada | Alta (10) | 3.8% | — | Adobe Shockwave Player | 14/7/2015 | 17/6/2026 | Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5120. | |
| Modificada | Alta (10) | 3.8% | — | Adobe Shockwave Player | 14/7/2015 | 17/6/2026 | Adobe Shockwave Player before 12.1.9.159 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5121. | |
| Modificada | Alta (10) | 4.7% | — | Wavelink Connectpro | 29/5/2015 | 17/6/2026 | Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header. | |
| Modificada | Alta (10) | 4.7% | — | Wavelink Terminal Emulation | 29/5/2015 | 17/6/2026 | Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header. | |
| Modificada | Alta (9) | 2.8% | — | Arubanetworks Airwave | 25/11/2014 | 17/6/2026 | The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Roguewaveproductionsllc Wild Women United | 16/10/2014 | 17/6/2026 | The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Wavea Toraware Takojyou | 4/10/2014 | 17/6/2026 | The Toraware Takojyou (aka ltd.pte.wavea.torawaretakojyou) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 2.7% | — | Trustwave ModsecurityDebian Linux | 15/4/2014 | 16/6/2026 | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header. | |
| Modificada | Alta (10) | 4.8% | — | Adobe Shockwave Player | 14/3/2014 | 17/6/2026 | Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. |