Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.8% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030. | |
| Analizada | Alta (8.8) | 68% | ⚠ Explotación activa | Adobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash PlayerAdobe AIR+13 | 28/12/2015 | 17/6/2026 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified… | |
| Modificada | Media (6.5) | 2.0% | — | HP Matrix Operating Environment | 27/8/2015 | 17/6/2026 | HP Matrix Operating Environment before 7.5.0 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Media (5) | 3.4% | — | HP Matrix Operating Environment | 27/8/2015 | 17/6/2026 | HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | HP Matrix Operating Environment | 27/8/2015 | 17/6/2026 | HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5428. | |
| Modificada | Alta (7.5) | 3.9% | — | HP Matrix Operating Environment | 27/8/2015 | 17/6/2026 | HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5429. | |
| Modificada | Alta (7.5) | 3.6% | — | HP Matrix Operating Environment | 27/8/2015 | 17/6/2026 | HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5428 and CVE-2015-5429. | |
| Modificada | Baja (3.5) | 0.95% | — | Webform Matrix Component Project Webform Matrix Component | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Webform Matrix Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Actian Matrix | 13/6/2015 | 17/6/2026 | Actian Matrix 5.1.x through 5.1.2.4 and 5.2.x through 5.2.0.1 allows remote authenticated users to bypass intended write-access restrictions and execute an UPDATE statement by referencing a table. | |
| Modificada | Media (6.4) | 1.4% | — | Tibco Activematrix Management AgentTibco Activematrix Policy AgentTibco Activematrix Policy Manager | 19/2/2015 | 17/6/2026 | The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1.2, ActiveMatrix Management Agent 1.x before 1.2.1 for WCF, and ActiveMatrix Management Agent 1.x before 1.2.1 for WebSphere allows remote attackers to gain privileges… | |
| Modificada | Media (6.8) | 2.7% | — | Inmatrix Zoom Player | 3/3/2014 | 16/6/2026 | Heap-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code via a large biClrUsed value in a BMP file. | |
| Modificada | Media (6.8) | 3.0% | — | Inmatrix Zoom Player | 3/3/2014 | 16/6/2026 | Stack-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code via a large biClrUsed value in a BMP file. | |
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Mw6tech Aztec Activex ControlMw6tech Datamatrix Activex ControlMw6tech Maxicode Activex Control | 21/1/2014 | 16/6/2026 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Matrix42 Service Store | 29/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Realmatrix Online Subtitles Workshop | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. | |
| Modificada | Media (5) | 1.2% | — | Tibco Activematrix BPMTibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 13/3/2012 | 16/6/2026 | The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to discover credentials via unspecified vectors. | |
| Modificada | Media (4.3) | 0.92% | — | Tibco Silver Fabric Activematrix Service Grid DistributionTibco Activematrix Service GridTibco Activematrix Service BUSTibco Activematrix Businessworks Service Engine+1 | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (5) | 1.4% | — | Tibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Businessworks Service EngineTibco Silver Fabric Activematrix Service Grid Distribution+3 | 13/3/2012 | 16/6/2026 | TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Squiz Mysource Matrix | 8/10/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Intendance Mysource Matrix | 30/12/2010 | 16/6/2026 | SQL injection vulnerability in index.php in MySource Matrix allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9) | 3.0% | — | Tibco Activematrix BPMTibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service Grid+2 | 17/12/2010 | 16/6/2026 | Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; ActiveMatrix BPM 1.0.1 and 1.0.2; Silver BPM Service 1.0.1; and Silver CAP Service 1.0.0 allows remote… | |
| Modificada | Alta (10) | 4.5% | — | Tibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Service Performance Manager | 26/10/2010 | 16/6/2026 | The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections,… | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Effectmatrix Magic Morph | 24/9/2009 | 16/6/2026 | Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Coronamatrix Phpaddressbook | 1/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Ajsquare AJ Matrix DNA | 17/8/2009 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action. |