Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.0%—Bigbluebutton2/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The…
ModificadaMedia (4.3)0.84%—Bigbluebutton2/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and…
ModificadaMedia (4.3)1.0%—Bigbluebutton2/6/202217/6/2026
BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of internal ids rather than on verification of…
ModificadaMedia (6.5)1.1%—Bigbluebutton1/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server.…
ModificadaAlta (7.5)1.6%—Bigbluebutton1/6/202217/6/2026
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service for the bbb-html5 service. The…
ModificadaMedia (6.5)0.92%—Jenkins Blue Ocean17/5/202217/6/2026
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
ModificadaMedia (6.5)0.73%—Jenkins Blue Ocean17/5/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server.
ModificadaMedia (6.5)1.0%—Jenkins Blue Ocean17/5/202217/6/2026
Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms3/5/202217/6/2026
Bluecms 1.6 has a SQL injection vulnerability at cooike.
ModificadaAlta (7.8)0.30%—Blueplanet-works Appguard12/4/202217/6/2026
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
ModificadaAlta (7.5)0.95%—Bluedon Internet Access Detector24/3/202217/6/2026
Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information leak which allows attackers to access the contents of the password file via unspecified vectors.
ModificadaAlta (8.8)1.8%—BluezFedoraproject FedoraDebian Linux10/3/202217/6/2026
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
ModificadaMedia (6.5)0.79%—BluezFedoraproject Fedora2/3/202217/6/2026
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby…
ModificadaMedia (6.1)0.89%—Bigbluebutton19/1/202217/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
ModificadaAlta (8.8)1.5%—BluezDebian Linux29/11/202117/6/2026
A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that are requested are appended to the output buffer. There are no size…
ModificadaMedia (6.5)1.0%—BluezDebian Linux29/11/202117/6/2026
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actually holds, resulting in leaking arbitrary heap data. The…
ModificadaMedia (6.5)1.2%—BluezDebian Linux12/11/202117/6/2026
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be…
ModificadaCrítica (9.1)1.7%—BluezDebian Linux4/11/202117/6/2026
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
ModificadaCrítica (9.8)1.6%—Microco BluemondayPython Pybluemonday18/10/202117/6/2026
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
ModificadaAlta (7.5)4.9%💥 ExploitBluespire Aurelia-path27/9/202117/6/2026
aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia…
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms8/9/202117/6/2026
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
ModificadaMedia (6.5)0.56%—MI True Wireless Earbuds Basic 2 FirmwareBluetrum Ab5376t FirmwareBluetrum Bt8896a Firmware7/9/202117/6/2026
The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data.
ModificadaMedia (6.5)0.41%—Bluetrum Ab5301a Firmware7/9/202117/6/2026
The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan…
ModificadaAlta (8.8)4.1%💥 ExploitBlue-admin Project Blue-admin30/8/202117/6/2026
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.
ModificadaMedia (5.3)0.40%—Bluetooth Core Specification25/6/202117/6/2026
Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent device to inject a crafted packet during the receive window of the listening device before the transmitting device initiates its packet transmission to achieve full MITM status without terminating…
Orbitaley — Vulnerabilidades