Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | LG Webos | 11/3/2022 | 17/6/2026 | The public API error causes for the attacker to be able to bypass API access control. | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Redhat Descision ManagerRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Process Automation+1 | 11/3/2022 | 17/6/2026 | A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. | |
| Modificada | Alta (7.8) | 0.23% | — | LG Webos | 28/1/2022 | 17/6/2026 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege | |
| Modificada | Media (6.1) | 0.56% | — | Bosch Video Security | 28/1/2022 | 17/6/2026 | HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker. | |
| Modificada | Media (5.3) | 1.1% | — | Buddyboss | 26/1/2022 | 17/6/2026 | BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is their private email address with symbols removed and periods replaced with hyphens. For example. JohnDoe@example.com would become… | |
| Modificada | Media (5.4) | 0.59% | — | Buddyboss | 26/1/2022 | 17/6/2026 | BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field. | |
| Modificada | Alta (7.8) | 0.24% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to… | |
| Modificada | Alta (7.1) | 0.14% | — | Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System | 19/1/2022 | 17/6/2026 | Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network… | |
| Modificada | Media (5.4) | 0.60% | — | Qibosoft | 27/12/2021 | 17/6/2026 | Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add. | |
| Modificada | Alta (8.8) | 0.56% | — | Qibosoft | 27/12/2021 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts. | |
| Modificada | Crítica (9.1) | 2.0% | — | Qibosoft | 27/12/2021 | 17/6/2026 | An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files. | |
| Modificada | Media (4.3) | 0.38% | — | Qibosoft | 27/12/2021 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL. | |
| Modificada | Alta (7.2) | 1.7% | — | Redhat Jboss Enterprise Application Platform | 23/12/2021 | 17/6/2026 | The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage. | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Alta (7.2) | 1.4% | — | Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware | 8/12/2021 | 17/6/2026 | A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000). | |
| Modificada | Media (6.5) | 0.83% | — | Bosch Video Management SystemBosch Video Recording Manager | 8/12/2021 | 17/6/2026 | By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed. | |
| Modificada | Media (6.1) | 0.51% | — | Bosch Video Management SystemBosch Video Recording Manager | 8/12/2021 | 17/6/2026 | An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed. | |
| Modificada | Alta (7.5) | 1.0% | — | Bosch Video Management SystemBosch Video Recording ManagerBosch Access Easy Controller FirmwareBosch Access Professional Edition+2 | 8/12/2021 | 17/6/2026 | An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering… | |
| Modificada | Media (4.8) | 0.70% | — | Imageboss | 23/11/2021 | 17/6/2026 | The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks | |
| Modificada | Media (6.5) | 1.5% | — | PostgresqlRedhat Jboss Enterprise Application Platform | 8/10/2021 | 17/6/2026 | A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality. | |
| Modificada | Media (6.8) | 0.15% | — | Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | 4/10/2021 | 17/6/2026 | An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password. | |
| Modificada | Media (6.8) | 0.43% | — | Bostonscientific Zoom Latitude Programming System Model 3120 FirmwareBostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | 4/10/2021 | 17/6/2026 | The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities. | |
| Modificada | Media (6.8) | 0.17% | — | Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | 4/10/2021 | 17/6/2026 | The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on the flash drive. An attacker could leverage this weakness to install unauthorized software using a specially crafted USB. | |
| Modificada | Media (6.4) | 0.23% | — | Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | 4/10/2021 | 17/6/2026 | An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engineer it, which could be used to create a physical duplicate of a valid hardware key. The hardware key allows access to special settings when inserted. | |
| Modificada | Alta (7.6) | 0.26% | — | Bostonscientific Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware | 4/10/2021 | 17/6/2026 | A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in the world. |