Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2395 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)13%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (6.5)14%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)6.7%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (5.5)0.87%—Realnetworks Realone Player3/7/201817/6/2026
RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.
ModificadaCrítica (9.8)8.4%—Westerndigital TV Live HUB FirmwareWesterndigital TV Media Player Firmware12/6/201817/6/2026
The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.
ModificadaAlta (8.8)3.7%—Videolan VLC Media Player28/5/201817/6/2026
The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.
ModificadaCrítica (9.8)8.6%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)26%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (6.5)25%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)26%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (6.5)20%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (6.5)4.1%—Adobe Flash PlayerAdobe Flash Player Desktop Runtime19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)5.1%—Adobe Flash PlayerAdobe Flash Player Desktop Runtime19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)7.6%—Adobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)7.4%—Adobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (7.2)14%💥 ExploitF5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+1213/4/201817/6/2026
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.
ModificadaAlta (7.8)4.7%💥 ExploitDvd-x-player DVD X Player1/4/201817/6/2026
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
ModificadaMedia (5.3)1.6%—Vmware Workstation PROVmware Workstation PlayerVmware Fusion15/3/201817/6/2026
VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled.
ModificadaAlta (8.8)5.0%—Adobe Shockwave Player19/2/201816/6/2026
Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.
AnalizadaAlta (7.8)90%⚠ Explotación activa💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation6/2/201817/6/2026
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and…
ModificadaCrítica (9.8)8.3%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation6/2/201817/6/2026
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
ModificadaAlta (7.5)5.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/1/201817/6/2026
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A…
ModificadaCrítica (9.6)3.8%—Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player4/1/201817/6/2026
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and…
ModificadaAlta (7.8)1.7%—Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player4/1/201817/6/2026
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and…
ModificadaAlta (8.8)2.2%—Videolan VLC Media PlayerDebian Linux15/12/201717/6/2026
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
Orbitaley — Vulnerabilidades