Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 13% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 14% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 6.7% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (5.5) | 0.87% | — | Realnetworks Realone Player | 3/7/2018 | 17/6/2026 | RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file. | |
| Modificada | Crítica (9.8) | 8.4% | — | Westerndigital TV Live HUB FirmwareWesterndigital TV Media Player Firmware | 12/6/2018 | 17/6/2026 | The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi. | |
| Modificada | Alta (8.8) | 3.7% | — | Videolan VLC Media Player | 28/5/2018 | 17/6/2026 | The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file. | |
| Modificada | Crítica (9.8) | 8.6% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 26% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.5) | 25% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 26% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.5) | 20% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.1% | — | Adobe Flash PlayerAdobe Flash Player Desktop Runtime | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Flash PlayerAdobe Flash Player Desktop Runtime | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 7.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 7.4% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (7.2) | 14% | 💥 Exploit | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+12 | 13/4/2018 | 17/6/2026 | On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced. | |
| Modificada | Alta (7.8) | 4.7% | 💥 Exploit | Dvd-x-player DVD X Player | 1/4/2018 | 17/6/2026 | DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. | |
| Modificada | Media (5.3) | 1.6% | — | Vmware Workstation PROVmware Workstation PlayerVmware Fusion | 15/3/2018 | 17/6/2026 | VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled. | |
| Modificada | Alta (8.8) | 5.0% | — | Adobe Shockwave Player | 19/2/2018 | 16/6/2026 | Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759. | |
| Analizada | Alta (7.8) | 90% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 6/2/2018 | 17/6/2026 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and… | |
| Modificada | Crítica (9.8) | 8.3% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 6/2/2018 | 17/6/2026 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 5.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/1/2018 | 17/6/2026 | An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A… | |
| Modificada | Crítica (9.6) | 3.8% | — | Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/1/2018 | 17/6/2026 | A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and… | |
| Modificada | Alta (7.8) | 1.7% | — | Cisco Webex Business SuiteCisco Webex MeetingsCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/1/2018 | 17/6/2026 | A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and… | |
| Modificada | Alta (8.8) | 2.2% | — | Videolan VLC Media PlayerDebian Linux | 15/12/2017 | 17/6/2026 | In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation. |