Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 1.0% | — | BluezCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 12/3/2020 | 17/6/2026 | Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access | |
| Modificada | Crítica (9.8) | 2.1% | — | Postoaktraffic Awam Bluetooth Field Device Firmware | 17/2/2020 | 17/6/2026 | Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter. | |
| Modificada | Media (6.5) | 1.0% | — | ST Wb55ST Bluenrg-2 | 12/2/2020 | 17/6/2026 | The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Protocol (ATT) requests on reception, allowing attackers in radio range to cause an event deadlock or crash via crafted packets. | |
| Modificada | Alta (8.1) | 4.5% | 💥 Exploit | Xmlblueprint | 30/12/2019 | 17/6/2026 | XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload. | |
| Modificada | Baja (3.3) | 0.28% | — | Bluboo S1 Project Blueboo S1 Firmware | 14/11/2019 | 17/6/2026 | The Bluboo Bluboo_S1 Android device with a build fingerprint of BLUBOO/Bluboo_S1/Bluboo_S1:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused… | |
| Modificada | Media (6.5) | 0.68% | — | Yalehome Yale Bluetooth KEY | 16/10/2019 | 17/6/2026 | The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale… | |
| Modificada | Media (6.5) | 0.91% | 💥 PoC | Bluestacks | 24/9/2019 | 17/6/2026 | An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (8) | 3.5% | — | Bluestacks APP Player | 23/6/2019 | 17/6/2026 | BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions. | |
| Modificada | Alta (8.8) | 2.2% | — | Blueprism Robotic Process Automation | 24/5/2019 | 17/6/2026 | In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information. The attack requires a valid user account to connect to the… | |
| Modificada | Alta (7.8) | 0.35% | — | Bluecats BC Reveal | 22/5/2019 | 17/6/2026 | The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need… | |
| Modificada | Alta (7.8) | 0.35% | — | Bluecats Reveal | 22/5/2019 | 17/6/2026 | The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the affected BlueCats network implementation.… | |
| Modificada | Alta (7.5) | 2.3% | — | Opensynergy Blue SDK | 29/3/2019 | 17/6/2026 | The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow remote, unauthenticated attackers to execute arbitrary code or cause a denial of service via malicious L2CAP configuration requests, in conjunction with crafted SDP communication over maliciously… | |
| Modificada | Crítica (9.8) | 1.5% | — | Bluecms Project Bluecms | 28/3/2019 | 17/6/2026 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes. | |
| Modificada | Crítica (9.8) | 1.5% | — | Bluecms Project Bluecms | 6/3/2019 | 17/6/2026 | BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | |
| Modificada | Alta (7.5) | 1.5% | — | Bluemind | 4/3/2019 | 17/6/2026 | In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads. | |
| Modificada | Media (5.4) | 1.2% | — | Jenkins Blue OceanRedhat Openshift Container Platform | 6/2/2019 | 17/6/2026 | An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java,… | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Blue OceanRedhat Openshift Container Platform | 6/2/2019 | 17/6/2026 | A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js,… | |
| Modificada | Baja (3.3) | 0.46% | — | BluezCanonical Ubuntu Linux | 28/1/2019 | 17/6/2026 | A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable. | |
| Modificada | Alta (8.8) | 0.57% | — | Bluestacks | 15/11/2018 | 17/6/2026 | BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass access restriction to gain unauthorized access. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 4/9/2018 | 17/6/2026 | BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. | |
| Analizada | Media (6.8) | 0.81% | — | TI Wl18xx Bluetooth Service PackGoogle AndroidApple Iphone OSApple MAC OS X | 7/8/2018 | 17/6/2026 | Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a… | |
| Modificada | Alta (7.2) | 2.5% | — | Blueriver Muracms | 26/2/2018 | 17/6/2026 | Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains… | |
| Modificada | Media (4.3) | 0.72% | — | Jenkins Blue Ocean | 5/10/2017 | 17/6/2026 | Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did not properly check the current user's authentication and authorization when configuring existing… | |
| Modificada | Alta (8.5) | 0.76% | — | Jenkins Blue Ocean | 5/10/2017 | 17/6/2026 | Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeline creation and editing feature in Blue Ocean. The SCM content… |