Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+1 | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. | |
| Modificada | Alta (7.5) | 0.69% | — | Dell Bsafe Micro-edition-suiteOracle Http ServerOracle Security ServiceOracle Weblogic Server Proxy Plug-in | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Chainsafe Lodestar | 24/5/2022 | 17/6/2026 | Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64` values as native javascript `number`s,… | |
| Modificada | Alta (7.8) | 11% | — | Rockwellautomation Connected Component WorkbenchRockwellautomation Isagraf WorkbenchRockwellautomation Safety Instrumented Systems Workstation | 17/5/2022 | 17/6/2026 | Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious serialized object that, if opened by a local… | |
| Modificada | Media (4.3) | 0.58% | — | F-secure Safe | 12/5/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks. | |
| Modificada | Alta (8.8) | 0.50% | — | F-secure Safe | 12/5/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop. | |
| Modificada | Alta (7.5) | 1.1% | — | Safedog Apache | 10/5/2022 | 17/6/2026 | In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data. | |
| Modificada | Crítica (9.8) | 1.8% | — | Csv-safe Project Csv-safe | 1/5/2022 | 17/6/2026 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. | |
| Modificada | Media (6.1) | 1.2% | — | 10up Safe SVG | 18/4/2022 | 17/6/2026 | The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of… | |
| Modificada | Media (4.3) | 0.46% | — | F-secure Safe | 15/4/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails. | |
| Modificada | Media (4.3) | 0.46% | — | F-secure Safe | 15/4/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the browser did not show full URL, such as port number. | |
| Modificada | Media (4.3) | 0.55% | — | F-secure Safe | 15/4/2022 | 17/6/2026 | An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled… | |
| Modificada | Media (5.5) | 2.2% | — | Rockwellautomation Connected Components WorkbenchRockwellautomation IsagrafRockwellautomation Safety Instrumented Systems Workstation | 1/4/2022 | 17/6/2026 | When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality. | |
| Modificada | Alta (7.5) | 0.95% | — | ABB 800xaABB Base SoftwareABB Compact Product SuiteABB Control Builder Safe | 1/4/2022 | 17/6/2026 | Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service. | |
| Modificada | Media (5.3) | 0.57% | — | F-secure Safe | 25/3/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS,… | |
| Modificada | Alta (7.4) | 0.50% | — | Chainsafe Js-libp2p-noise | 17/3/2022 | 17/6/2026 | `@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers… | |
| Modificada | Crítica (9.1) | 0.97% | — | Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+88 | 14/3/2022 | 17/6/2026 | The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows… | |
| Modificada | Alta (7.8) | 0.18% | — | Blackberry QNX MomenticsBlackberry QNX Software Development PlatformBlackberry QNX OS FOR MedicalBlackberry QNX OS FOR Safety | 10/3/2022 | 17/6/2026 | An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX… | |
| Modificada | Crítica (9.6) | 0.82% | — | F-secure Safe | 6/3/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution. | |
| Modificada | Media (6.1) | 0.55% | — | F-secure Safe | 6/3/2022 | 17/6/2026 | A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerability can be exploited remotely by an attacker to execute the JavaScript can be used to trigger universal cross-site scripting through the browser. User interaction is required prior to exploitation,… | |
| Modificada | Media (6.2) | 0.15% | — | Stsafe-j FirmwareST J-safe3 Firmware | 4/3/2022 | 17/6/2026 | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN… | |
| Modificada | Media (6.2) | 0.16% | — | ST J-safe3 FirmwareStsafe-j Firmware | 4/3/2022 | 17/6/2026 | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed… | |
| Modificada | Alta (7.5) | 0.96% | — | Dell Bsafe Ssl-j | 23/2/2022 | 17/6/2026 | Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can receive details about this vulnerability. Public disclosure of the vulnerability details will be shared… | |
| Modificada | Crítica (9.8) | 1.1% | — | Tibco Auditsafe | 15/2/2022 | 17/6/2026 | The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute API methods on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO AuditSafe: versions 1.1.0 and below. | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… |