Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Lemurmonitors Bluedriver | 22/4/2016 | 17/6/2026 | The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or… | |
| Modificada | Alta (8.4) | 6.3% | 💥 Exploit | Blueman Project Blueman | 8/1/2016 | 17/6/2026 | The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dhcp_handler argument. | |
| Modificada | Alta (7.4) | 1.9% | — | Bluecoat ProxysgBluecoat Advanced Secure Gateway | 8/1/2016 | 17/6/2026 | Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by… | |
| Modificada | Baja (2.1) | 0.31% | — | Bluecoat Unified Agent | 7/12/2015 | 17/6/2026 | Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enforcement mode, which allows local administrators to unblock categories or disable the agent via unspecified vectors. | |
| Modificada | Media (6.8) | 1.6% | — | Cisco Edge Bluebird Operating System | 19/8/2015 | 17/6/2026 | The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968. | |
| Modificada | Media (4.3) | 1.4% | — | Blue Coat SSL Visibility Appliance Sv1800 FirmwareBlue Coat SSL Visibility Appliance Sv800 FirmwareBlue Coat SSL Visibility Appliance Sv3800 FirmwareBlue Coat SSL Visibility Appliance Sv2800 Firmware | 30/5/2015 | 17/6/2026 | The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access… | |
| Modificada | Media (4.3) | 1.4% | — | Blue Coat SSL Visibility Appliance Sv800 FirmwareBlue Coat SSL Visibility Appliance Sv1800 FirmwareBlue Coat SSL Visibility Appliance Sv3800 FirmwareBlue Coat SSL Visibility Appliance Sv2800 Firmware | 30/5/2015 | 17/6/2026 | The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http… | |
| Modificada | Media (4.3) | 1.4% | — | Blue Coat SSL Visibility Appliance Sv800 FirmwareBlue Coat SSL Visibility Appliance Sv1800 FirmwareBlue Coat SSL Visibility Appliance Sv2800 FirmwareBlue Coat SSL Visibility Appliance Sv3800 Firmware | 30/5/2015 | 17/6/2026 | The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element. | |
| Modificada | Media (6.8) | 1.5% | — | Blue Coat SSL Visibility Appliance Sv3800 FirmwareBlue Coat SSL Visibility Appliance Sv2800 FirmwareBlue Coat SSL Visibility Appliance Sv1800 FirmwareBlue Coat SSL Visibility Appliance Sv800 Firmware | 30/5/2015 | 17/6/2026 | Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web sessions by providing a session ID. | |
| Modificada | Media (4.3) | 0.69% | — | Blue Coat SSL Visibility Appliance Sv2800 FirmwareBlue Coat SSL Visibility Appliance Sv1800 FirmwareBlue Coat SSL Visibility Appliance Sv3800 FirmwareBlue Coat SSL Visibility Appliance Sv800 Firmware | 30/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | NEW Atlanta Bluedragon | 21/4/2015 | 17/6/2026 | Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart. | |
| Modificada | Media (5) | 1.4% | — | Blue Coat Malware Analysis Appliance | 17/4/2015 | 17/6/2026 | search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matching keywords in conjunction with a crafted parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Blue Coat Malware Analysis Appliance | 17/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.9) | 0.38% | — | Toshiba Bluetooth StackToshiba Service Station | 28/2/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Alta (7.1) | 0.70% | — | Bluecoat ProxyclientBluecoat Unified Agent | 2/2/2015 | 17/6/2026 | Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted… | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Joint Radio Blues | 21/10/2014 | 17/6/2026 | The Joint Radio Blues (aka com.nobexinc.wls_69685189.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Bluemasters | 8/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings. | |
| Modificada | Media (5.4) | 0.27% | — | Blueeleph Project Blueeleph | 29/9/2014 | 17/6/2026 | The blueeleph (aka eg.film.blueeleph) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Perblue Parallel Kingdom MMO | 9/9/2014 | 17/6/2026 | The Parallel Kingdom MMO (aka com.silvermoon.client) application @7F070019 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 0.72% | — | Bluecoat Content Analysis System SoftwareBluecoat Content Analysis System | 30/4/2014 | 17/6/2026 | The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection." | |
| Modificada | Alta (7.9) | 1.0% | — | Bluecoat Proxysgos | 2/3/2014 | 17/6/2026 | The caching feature in SGOS in Blue Coat ProxySG 5.5 through 5.5.11.3, 6.1 through 6.1.6.3, 6.2 through 6.2.15.3, 6.4 through 6.4.6.1, and 6.3 and 6.5 before 6.5.4 allows remote authenticated users to bypass intended access restrictions during a time window after account deletion or modification by leveraging… | |
| Modificada | Media (6.8) | 31% | 💥 Exploit | Skybluecanvas | 29/1/2014 | 17/6/2026 | The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php. | |
| Modificada | Alta (9.3) | 6.4% | — | Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software | 21/1/2014 | 16/6/2026 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed… | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Sunil Nanda Blue Wrench Video Widget | 19/11/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed arbitrary URLs via the bw_url parameter in the bw-videos page to… | |
| Modificada | Alta (7.1) | 1.5% | — | Bluecoat ProxysgosBluecoat Proxysg | 28/9/2013 | 16/6/2026 | Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of service (memory consumption and dropped connections) via a recursive href in an HTML page, which triggers a large number of HTTP RW pipeline pre-fetch requests. |