Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

453 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)30%💥 PoCJqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+4318/1/201817/6/2026
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
ModificadaAlta (7.5)0.42%—Philips HUE Bridge Bsb002 Firmware1/10/201717/6/2026
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet…
ModificadaAlta (7.8)1.1%—Fujixerox Contentsbridge Utility1/9/201717/6/2026
Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.1)1.2%—Qodeinteractive Bridge23/8/201717/6/2026
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
ModificadaAlta (7.5)0.51%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.
ModificadaAlta (7.5)1.1%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.
ModificadaAlta (8.8)0.45%—Lenovo Service Bridge4/6/201717/6/2026
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
ModificadaAlta (7.8)0.37%—Lenovo Service Bridge4/6/201717/6/2026
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
ModificadaCrítica (9.8)1.7%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
ModificadaAlta (8.8)0.64%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY).
ModificadaAlta (8.6)1.7%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
ModificadaAlta (7.1)0.94%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application.
ModificadaCrítica (9.8)20%💥 ExploitAdobe Bridge CCAdobe Photoshop CC10/2/201617/6/2026
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.
ModificadaCrítica (9.8)20%💥 ExploitAdobe Bridge CCAdobe Photoshop CC10/2/201617/6/2026
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.
ModificadaCrítica (9.8)20%💥 ExploitAdobe Bridge CCAdobe Photoshop CC10/2/201617/6/2026
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.
ModificadaAlta (8.8)1.4%💥 ExploitMediabridge Medialink Mwn-wapr300n Firmware31/12/201517/6/2026
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaCrítica (9.8)19%💥 ExploitTenda N3 Wireless N150Mediabridge Medialink Mwn-wapr300n Firmware31/12/201517/6/2026
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.
ModificadaMedia (6.8)1.3%—Mediabridge Medialink Mwn-wapr300n Firmware31/12/201517/6/2026
The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the medialink account, which allows remote attackers to obtain administrative privileges by leveraging a Wi-Fi session.
ModificadaAlta (10)14%💥 ExploitAdobe BridgeAdobe Photoshop CC24/6/201517/6/2026
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
ModificadaAlta (10)19%💥 ExploitAdobe BridgeAdobe Photoshop CC24/6/201517/6/2026
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)17%💥 ExploitAdobe Photoshop CCAdobe Bridge24/6/201517/6/2026
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)2.1%—Google Android Debug BridgeGoogle Android SDK Platform ToolsOpensuse14/5/201417/6/2026
Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow.
ModificadaMedia (6.8)3.4%—Cambridge Enterprise Jbig-kit11/4/201417/6/2026
Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.
ModificadaBaja (3.3)0.27%—Google Android Debug Bridge14/2/201316/6/2026
android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.
ModificadaAlta (7.1)1.8%—IBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges31/1/201316/6/2026
InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.
Orbitaley — Vulnerabilidades