Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—LG Webos11/3/202217/6/2026
The public API error causes for the attacker to be able to bypass API access control.
ModificadaAlta (7.5)1.5%💥 PoCRedhat Descision ManagerRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Process Automation+111/3/202217/6/2026
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
ModificadaAlta (7.8)0.23%—LG Webos28/1/202217/6/2026
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege
ModificadaMedia (6.1)0.56%—Bosch Video Security28/1/202217/6/2026
HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.
ModificadaMedia (5.3)1.1%—Buddyboss26/1/202217/6/2026
BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is their private email address with symbols removed and periods replaced with hyphens. For example. JohnDoe@example.com would become…
ModificadaMedia (5.4)0.59%—Buddyboss26/1/202217/6/2026
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
ModificadaAlta (7.8)0.24%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to…
ModificadaAlta (7.1)0.14%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network…
ModificadaMedia (5.4)0.60%—Qibosoft27/12/202117/6/2026
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
ModificadaAlta (8.8)0.56%—Qibosoft27/12/202117/6/2026
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.
ModificadaCrítica (9.1)2.0%—Qibosoft27/12/202117/6/2026
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
ModificadaMedia (4.3)0.38%—Qibosoft27/12/202117/6/2026
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
ModificadaAlta (7.2)1.7%—Redhat Jboss Enterprise Application Platform23/12/202117/6/2026
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaAlta (7.2)1.4%—Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware8/12/202117/6/2026
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).
ModificadaMedia (6.5)0.83%—Bosch Video Management SystemBosch Video Recording Manager8/12/202117/6/2026
By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
ModificadaMedia (6.1)0.51%—Bosch Video Management SystemBosch Video Recording Manager8/12/202117/6/2026
An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
ModificadaAlta (7.5)1.0%—Bosch Video Management SystemBosch Video Recording ManagerBosch Access Easy Controller FirmwareBosch Access Professional Edition+28/12/202117/6/2026
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering…
ModificadaMedia (4.8)0.70%—Imageboss23/11/202117/6/2026
The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks
ModificadaMedia (6.5)1.5%—PostgresqlRedhat Jboss Enterprise Application Platform8/10/202117/6/2026
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
ModificadaMedia (6.8)0.15%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.
ModificadaMedia (6.8)0.43%—Bostonscientific Zoom Latitude Programming System Model 3120 FirmwareBostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities.
ModificadaMedia (6.8)0.17%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB.
ModificadaMedia (6.4)0.23%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted.
ModificadaAlta (7.6)0.26%—Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware4/10/202117/6/2026
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world.
Orbitaley — Vulnerabilidades