Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Foliovision FV Flowplayer Video Player | 9/8/2019 | 17/6/2026 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | |
| Modificada | Media (6.1) | 2.0% | — | Foliovision FV Flowplayer Video Player | 9/8/2019 | 17/6/2026 | The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. | |
| Modificada | Crítica (9.8) | 2.4% | — | Imgtech Zoneplayer | 2/8/2019 | 17/6/2026 | ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution. | |
| Modificada | Media (5.5) | 2.5% | — | Videolan VLC Media PlayerOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | Double Free in VLC versions <= 3.0.6 leads to a crash. | |
| Modificada | Alta (7.1) | 2.8% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. | |
| Modificada | Media (6.5) | 0.88% | — | Unity WEB Player | 29/7/2019 | 17/6/2026 | The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials | |
| Modificada | Crítica (9.8) | 3.7% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 18/7/2019 | 17/6/2026 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. | |
| Modificada | Crítica (9.8) | 4.4% | — | Foliovision FV Flowplayer Video Player | 17/7/2019 | 17/6/2026 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |
| Modificada | Media (5.5) | 2.5% | — | Videolan VLC Media Player | 16/7/2019 | 17/6/2026 | libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement. | |
| Modificada | Alta (7.8) | 2.1% | — | Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 14/7/2019 | 17/6/2026 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file. | |
| Modificada | Alta (8) | 3.5% | — | Bluestacks APP Player | 23/6/2019 | 17/6/2026 | BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions. | |
| Modificada | Crítica (9.8) | 2.4% | — | Videolan VLC Media Player | 18/6/2019 | 17/6/2026 | An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free. | |
| Modificada | Media (6.5) | 5.3% | — | Videolan VLC Media Player | 13/6/2019 | 17/6/2026 | A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit. | |
| Modificada | Alta (8.8) | 5.5% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 12/6/2019 | 17/6/2026 | Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (6.5) | 4.8% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 24/5/2019 | 17/6/2026 | Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information… | |
| Modificada | Alta (7.5) | 3.2% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 23/5/2019 | 17/6/2026 | Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure . | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 6.2% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 23/5/2019 | 17/6/2026 | Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 9.7% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 22/5/2019 | 17/6/2026 | Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. |