Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.8% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 2.8% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 2.8% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Baja (3.3) | 2.0% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 2.6% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.8) | 2.8% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 5.2% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have a stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.8% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Baja (3.3) | 2.1% | — | Adobe Bridge | 26/6/2020 | 17/6/2026 | Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 0.48% | — | Gns3 Ubridge | 23/6/2020 | 17/6/2026 | GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration file while executing in a setuid root context. | |
| Modificada | Media (4.5) | 0.52% | — | Philips Intellibridge Enterprise | 11/6/2020 | 17/6/2026 | Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the transaction logs, which are secured behind… | |
| Modificada | Alta (7.5) | 1.8% | — | Atto Fibrebridge 7500n Firmware | 7/5/2020 | 17/6/2026 | ATTO FibreBridge 7500N firmware versions prior to 2.90 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause Denial of Service (DoS). | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.8) | 0.36% | — | LG Bridge | 29/4/2020 | 17/6/2026 | An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur. | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Alta (7.8) | 5.8% | — | Adobe Bridge | 25/3/2020 | 17/6/2026 | Adobe Bridge versions 10.0 have a heap-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.9% | — | Adobe Bridge | 25/3/2020 | 17/6/2026 | Adobe Bridge versions 10.0 have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.9) | 2.1% | — | Philips HUE Bridge V2 Firmware | 23/1/2020 | 17/6/2026 | Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution. | |
| Modificada | Media (6.5) | 0.33% | — | Philips Intellibridge Ec40 FirmwarePhilips Intellibridge Ec80 Firmware | 26/11/2019 | 17/6/2026 | In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers. This could enable an unauthorized attacker with access to the network to capture and replay the session and gain… | |
| Modificada | Alta (7.5) | 2.5% | — | Adobe Bridge CC | 14/11/2019 | 17/6/2026 | Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 2.5% | — | Adobe Bridge CC | 14/11/2019 | 17/6/2026 | Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.5) | 0.37% | — | Belwith-keeler Hickory Smart Ethernet Bridge Firmware | 22/8/2019 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates over the network to an MQTT broker without using encryption. This exposed the default username and… | |
| Modificada | Media (6.5) | 2.9% | — | Adobe Bridge CC | 18/7/2019 | 17/6/2026 | Adobe Bridge CC version 9.0.2 and earlier versions have an out of bound read vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Alta (7.5) | 0.76% | — | Lenovo Service Bridge | 26/6/2019 | 17/6/2026 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP. |