Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)5.0%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (8.8)5.0%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (8.8)8.3%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (6.5)3.3%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound read vulnerability. Successful exploitation could lead to memory leak.
ModificadaAlta (8.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)7.3%—Adobe Photoshop CC26/8/201917/6/2026
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)90%💥 ExploitZeroshell19/7/201917/6/2026
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
ModificadaAlta (7.8)0.29%—Cloud Foundry Bosh19/6/201917/6/2026
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.
ModificadaAlta (7.8)5.1%💥 ExploitPhotodex Proshow Producer10/6/201917/6/2026
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a buffer overflow via a crafted file.
ModificadaCrítica (9.8)6.4%—Adobe Photoshop CC24/5/201917/6/2026
Adobe Photoshop CC 19.1.7 and earlier, and 20.0.2 and earlier have a heap corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (5.4)0.72%—Kieranoshea Calendar13/5/201917/6/2026
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI.
ModificadaCrítica (9.8)3.0%—Coship Rt3052 FirmwareCoship Rt3050 FirmwareCoship Wm3300 FirmwareCoship Rt7620 Firmware7/5/201917/6/2026
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.
ModificadaAlta (7.1)0.58%—Cloudfoundry Bosh Backup AND Restore24/4/201917/6/2026
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in…
ModificadaCrítica (9.8)54%💥 ExploitCoship Rt3050 FirmwareCoship Rt3052 FirmwareCoship Rt7620 FirmwareCoship Wm3300 Firmware21/3/201917/6/2026
An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request…
ModificadaAlta (8.8)0.60%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.
ModificadaAlta (8.8)0.65%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.
ModificadaMedia (6.1)0.79%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.47%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device.