Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.5% | — | Lenovo Service Bridge | 26/6/2019 | 17/6/2026 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. | |
| Modificada | Crítica (9.8) | 2.5% | — | Lenovo Service Bridge | 26/6/2019 | 17/6/2026 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. | |
| Modificada | Alta (8.8) | 0.48% | — | Lenovo Service Bridge | 26/6/2019 | 17/6/2026 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. | |
| Modificada | Media (6.5) | 4.0% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.7% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.0% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an use after free vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.0% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.0% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 3.8% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 6.0% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have an out-of-bounds write vulnerability. Successful exploitation could lead to remote code execution. | |
| Modificada | Crítica (9.8) | 6.4% | — | Adobe Bridge CC | 23/5/2019 | 17/6/2026 | Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution. | |
| Modificada | Crítica (9.8) | 2.0% | — | THE University OF Cambridge WEB Authentication System Apache Authentication Agent | 13/5/2019 | 17/6/2026 | Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the rest of the message, and manipulation is therefore trivial. The… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.3% | — | Atto Fibrebridge 7500n Firmware | 12/2/2019 | 17/6/2026 | ATTO FibreBridge 7500N firmware version 2.95 is susceptible to a vulnerability which allows attackers to cause a Denial of Service (DoS). | |
| Modificada | Media (6.5) | 7.3% | — | GrafanaRedhat Ceph StorageRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 13/12/2018 | 17/6/2026 | Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. | |
| Modificada | Alta (8.8) | 1.0% | — | Microfocus Operations Bridge | 7/11/2018 | 17/6/2026 | A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure. | |
| Modificada | Crítica (9.8) | 2.4% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+4 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Crítica (9.8) | 3.1% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+1 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Alta (7.5) | 1.1% | — | Airbridge Dmptoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for DMPToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.3% | — | Bwssystems HA Bridge | 28/6/2018 | 17/6/2026 | BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI. | |
| Modificada | Media (6.1) | 2.1% | — | GrafanaNetapp Active IQ Performance Analytics ServicesNetapp Storagegrid Webscale NAS Bridge | 11/6/2018 | 17/6/2026 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. | |
| Modificada | Alta (8.8) | 1.6% | — | Sitebridge Joruri GW | 14/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP code via unspecified vectors. | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Westernbridgegroup Razor | 11/3/2018 | 17/6/2026 | A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php. | |
| Modificada | Alta (8.8) | 0.78% | — | HTC Customer-link BridgeVolkswagen Customer-link | 2/3/2018 | 17/6/2026 | This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Customer-Link App and… | |
| Modificada | Media (5.4) | 0.56% | — | HP Operations Bridge Analytics | 15/2/2018 | 17/6/2026 | A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found. |