Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.45%—Bluez10/6/202117/6/2026
The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
ModificadaMedia (5.7)0.83%—BluezRedhat Enterprise LinuxDebian Linux9/6/202117/6/2026
Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
ModificadaAlta (8.1)0.85%—Bluetooth Mesh Profile24/5/202117/6/2026
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.
ModificadaAlta (8.8)0.85%—Bluetooth Mesh Profile24/5/202117/6/2026
Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device…
ModificadaMedia (4.2)0.87%—Bluetooth Core SpecificationFedoraproject FedoraDebian LinuxLinux Kernel+1524/5/202117/6/2026
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device,…
ModificadaAlta (7.5)0.83%—Bluetooth Mesh Profile24/5/202117/6/2026
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).
ModificadaAlta (7.5)0.91%—Bluetooth Core SpecificationBluetooth Mesh Profile24/5/202117/6/2026
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment.
ModificadaMedia (5.4)0.88%—Bluetooth Core SpecificationFedoraproject FedoraIntel Ax210 FirmwareIntel Ax201 Firmware+1324/5/202117/6/2026
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.
ModificadaMedia (5.4)0.62%—Bluemedicinelabs Hotjar Connecticator24/5/202117/6/2026
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.
ModificadaMedia (6.1)1.4%—Bluespire Aurelia Framework13/5/202117/6/2026
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attribute of various…
ModificadaMedia (6.1)0.93%—Microco Bluemonday27/3/202117/6/2026
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
ModificadaAlta (8.1)0.64%—Elementary Switchboard Bluetooth PlugFedoraproject Fedora12/3/202117/6/2026
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers…
ModificadaMedia (6.5)2.2%💥 PoCBluez2/2/202117/6/2026
Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.
ModificadaCrítica (9.8)2.1%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue26/1/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
ModificadaAlta (7.5)1.5%—Bigbluebutton26/11/202017/6/2026
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.
ModificadaBaja (3.7)1.1%—Bigbluebutton26/11/202017/6/2026
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
ModificadaMedia (5.3)1.3%—Bigbluebutton19/11/202017/6/2026
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
ModificadaMedia (4.3)0.70%—Bigbluebutton19/11/202017/6/2026
In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.
ModificadaAlta (7.8)0.33%—Bluestacks10/11/202017/6/2026
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.
ModificadaAlta (7)4.6%💥 ExploitBlueman Project BluemanDebian LinuxFedoraproject Fedora27/10/202017/6/2026
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argument injection vulnerability. The impact highly depends on the system configuration. If Polkit-1 is disabled and for versions lower than 2.0.6, any local user can possibly…
ModificadaMedia (6.5)0.86%—HP Bluedata EpicHP Ezmeral Container Platform26/10/202017/6/2026
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url…
ModificadaMedia (6.1)0.81%—Bigbluebutton Greenlight22/10/202017/6/2026
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
ModificadaAlta (8.4)0.27%—Bigbluebutton21/10/202017/6/2026
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
ModificadaMedia (4.3)0.68%—Bigbluebutton21/10/202017/6/2026
Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a browser window.
ModificadaAlta (7.3)0.66%—Bigbluebutton21/10/202017/6/2026
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
Orbitaley — Vulnerabilidades