Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

694 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.3%—Esri Arcgisruntime SDK29/3/201817/6/2026
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
ModificadaCrítica (9.8)3.1%—3s-software Codesys Runtime System3s-software Codesys WEB Server15/2/201817/6/2026
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3, or as part of the CODESYS runtime system running prior to Version V1.1.9.19. A crafted request may cause a buffer overflow and…
ModificadaMedia (6.5)3.6%—Adobe Flash PlayerAdobe Flash Player Desktop RuntimeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+113/12/201717/6/2026
A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.
ModificadaAlta (8.8)1.0%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
ModificadaAlta (8.8)0.76%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
ModificadaMedia (4.7)0.60%—Apache Portable Runtime Utility24/10/201717/6/2026
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial…
ModificadaAlta (7.1)1.7%—Apache Portable RuntimeDebian LinuxRedhat Jboss Core ServicesRedhat Jboss Enterprise WEB Server+724/10/201717/6/2026
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting…
AnalizadaAlta (8.8)12%⚠ Explotación activaAdobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+122/10/201717/6/2026
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
ModificadaAlta (8.8)1.2%—Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime7/9/201717/6/2026
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations…
ModificadaAlta (8.8)22%💥 ExploitRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux WorkstationAdobe Flash Player Desktop Runtime+111/8/201717/6/2026
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.4)4.5%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+111/8/201717/6/2026
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
ModificadaMedia (6.5)3.7%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure.
ModificadaAlta (8.8)8.6%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (6.5)4.2%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.3)1.5%💥 ExploitIBM Data Server ClientIBM Data Server Driver FOR Odbc AND CLIIBM Data Server Driver PackageIBM Data Server Runtime Client+227/6/201717/6/2026
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
ModificadaAlta (7.1)0.37%—IBM Data Server ClientIBM Data Server Driver FOR Odbc AND CLIIBM Data Server Driver PackageIBM Data Server Runtime Client+227/6/201717/6/2026
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
ModificadaAlta (8.8)1.3%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and…
ModificadaCrítica (9.8)1.4%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.
ModificadaCrítica (9.8)2.1%—Pivotal Software Cloud Foundry Elastic Runtime13/6/201717/6/2026
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple…
ModificadaAlta (8.1)1.2%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+125/5/201717/6/2026
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given…
ModificadaMedia (6.5)0.86%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime25/5/201717/6/2026
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly…
ModificadaMedia (6.1)0.66%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+125/5/201717/6/2026
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes…
ModificadaAlta (7.5)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime25/5/201717/6/2026
It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attacker could use an improper disk quota value to bypass enforcement…
Orbitaley — Vulnerabilidades