Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.50% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 9/1/2019 | 17/6/2026 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to bypass access restriction to access the information and files stored on the affected device. | |
| Modificada | Alta (7.5) | 7.9% | — | Adobe Photoshop CC | 29/11/2018 | 17/6/2026 | Adobe Photoshop CC versions 19.1.6 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 PoC | Tuyoshi Jquery Picture CUT | 5/11/2018 | 17/6/2026 | Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta | |
| Modificada | Alta (8.1) | 1.5% | — | Cloud Foundry Bosh | 5/10/2018 | 17/6/2026 | Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens when using UAA for authentication. A remote attacker with an admin refresh token given by UAA can be used to access BOSH resources without… | |
| Modificada | Crítica (9.8) | 6.5% | — | Adobe Photoshop CC | 29/8/2018 | 17/6/2026 | Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution. | |
| Modificada | Crítica (9.8) | 6.5% | — | Adobe Photoshop CC | 29/8/2018 | 17/6/2026 | Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution. | |
| Modificada | Alta (8.8) | 8.0% | — | Adobe Photoshop CC | 9/7/2018 | 17/6/2026 | Adobe Photoshop CC versions 19.1.3 and earlier, 18.1.3 and earlier, and 18.1.2 and earlier have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Coship Rt3052 Firmware | 10/4/2018 | 17/6/2026 | Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. | |
| Modificada | Alta (8.8) | 0.97% | — | Pivotal Software Bosh CLI | 27/3/2018 | 17/6/2026 | Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH. | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry Cf-releasePivotal UAAPivotal UAA Bosh | 4/1/2018 | 17/6/2026 | An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID… | |
| Modificada | Crítica (9.8) | 7.1% | — | Adobe Photoshop | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 8.1% | — | Adobe Photoshop | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9) | 1.4% | — | Intel Nuc7i3bnk BiosIntel Nuc7i5bnk BiosIntel Nuc7i7bnh BiosIntel Stk2mv64cc Bios+18 | 26/7/2017 | 17/6/2026 | Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state. | |
| Modificada | Media (6.6) | 0.88% | — | Pivotal Software Cloud Foundry UAACloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CF | 10/7/2017 | 17/6/2026 | In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to… | |
| Modificada | Alta (8.8) | 0.77% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.0% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.4% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges. | |
| Modificada | Crítica (9.8) | 1.5% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.8% | — | Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware | 7/7/2017 | 17/6/2026 | Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Douroshisetu Kihon Data Sakusei System | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in Douroshisetu Kihon Data Sakusei System Ver1.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.5) | 1.1% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior… | |
| Modificada | Alta (7.2) | 0.94% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions… | |
| Modificada | Media (6.5) | 0.97% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior… | |
| Modificada | Alta (8.8) | 1.1% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior… |