Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.80% | — | Intland Codebeamer | 30/3/2020 | 17/6/2026 | In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file. | |
| Modificada | Alta (7.5) | 1.0% | — | Apache Beam | 15/1/2020 | 17/6/2026 | The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code… | |
| Modificada | Crítica (9.8) | 1.7% | — | Crossbeam Project Crossbeam | 26/8/2019 | 17/6/2026 | An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestXmlbeam | 11/5/2018 | 26/6/2026 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference… | |
| Modificada | Alta (7.5) | 1.1% | — | Liveqos Superbeam | 19/12/2017 | 17/6/2026 | SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection. | |
| Modificada | Baja (3.3) | 1.1% | — | Samsung S-beam | 6/7/2015 | 17/6/2026 | Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Joomla COM Beamospetition | 2/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Joomla COM Beamospetition | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM Beamospetition | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Counterpath Eyebeam SIP Softphone | 22/1/2006 | 16/6/2026 | Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent… |