Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (7.5) | 0.42% | — | Philips HUE Bridge Bsb002 Firmware | 1/10/2017 | 17/6/2026 | Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet… | |
| Modificada | Alta (7.8) | 1.1% | — | Fujixerox Contentsbridge Utility | 1/9/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 1.2% | — | Qodeinteractive Bridge | 23/8/2017 | 17/6/2026 | DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript. | |
| Modificada | Alta (7.5) | 0.51% | — | Lenovo Service Bridge | 4/6/2017 | 17/6/2026 | In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate. | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Service Bridge | 4/6/2017 | 17/6/2026 | In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers. | |
| Modificada | Alta (8.8) | 0.45% | — | Lenovo Service Bridge | 4/6/2017 | 17/6/2026 | A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed. | |
| Modificada | Alta (7.8) | 0.37% | — | Lenovo Service Bridge | 4/6/2017 | 17/6/2026 | In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges. | |
| Modificada | Crítica (9.8) | 1.7% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials. | |
| Modificada | Alta (8.8) | 0.64% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY). | |
| Modificada | Alta (8.6) | 1.7% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication. | |
| Modificada | Alta (7.1) | 0.94% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953. | |
| Modificada | Alta (8.8) | 1.4% | 💥 Exploit | Mediabridge Medialink Mwn-wapr300n Firmware | 31/12/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Tenda N3 Wireless N150Mediabridge Medialink Mwn-wapr300n Firmware | 31/12/2015 | 17/6/2026 | Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header. | |
| Modificada | Media (6.8) | 1.3% | — | Mediabridge Medialink Mwn-wapr300n Firmware | 31/12/2015 | 17/6/2026 | The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the medialink account, which allows remote attackers to obtain administrative privileges by leveraging a Wi-Fi session. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Adobe BridgeAdobe Photoshop CC | 24/6/2015 | 17/6/2026 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Alta (10) | 19% | 💥 Exploit | Adobe BridgeAdobe Photoshop CC | 24/6/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Adobe Photoshop CCAdobe Bridge | 24/6/2015 | 17/6/2026 | Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Google Android Debug BridgeGoogle Android SDK Platform ToolsOpensuse | 14/5/2014 | 17/6/2026 | Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow. | |
| Modificada | Media (6.8) | 3.4% | — | Cambridge Enterprise Jbig-kit | 11/4/2014 | 17/6/2026 | Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file. | |
| Modificada | Baja (3.3) | 0.27% | — | Google Android Debug Bridge | 14/2/2013 | 16/6/2026 | android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log. | |
| Modificada | Alta (7.1) | 1.8% | — | IBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges | 31/1/2013 | 16/6/2026 | InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors. |