Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.80%—Intland Codebeamer30/3/202017/6/2026
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.
ModificadaAlta (7.5)1.0%—Apache Beam15/1/202017/6/2026
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code…
ModificadaCrítica (9.8)1.7%—Crossbeam Project Crossbeam26/8/201917/6/2026
An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.
ModificadaAlta (7.5)4.9%💥 PoCBroadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestXmlbeam11/5/201826/6/2026
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference…
ModificadaAlta (7.5)1.1%—Liveqos Superbeam19/12/201717/6/2026
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.
ModificadaBaja (3.3)1.1%—Samsung S-beam6/7/201517/6/2026
Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000.
ModificadaMedia (4.3)1.5%💥 ExploitJoomla COM Beamospetition2/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.
ModificadaAlta (7.5)0.99%💥 ExploitJoomla COM Beamospetition2/2/200916/6/2026
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM Beamospetition10/7/200816/6/2026
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.
ModificadaAlta (7.5)4.0%💥 ExploitCounterpath Eyebeam SIP Softphone22/1/200616/6/2026
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent…
Orbitaley — Vulnerabilidades