Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.16%—Black Duck SCAAI21/11/202517/6/2026
Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not…
AnalizadaMedia (5)0.19%—Blackberry Athoc19/11/202517/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS).
AplazadaCrítica (9.6)0.71%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
AplazadaCrítica (9.6)0.48%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
AplazadaMedia (4.7)0.23%—GitlabAIBlacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
AplazadaMedia (4.7)0.23%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.
AnalizadaCrítica (9.8)0.55%—Blackmagicdesign Atem Mini PRO Firmware22/9/202517/6/2026
The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and even internal…
AplazadaAlta (7.5)0.28%—Blackmagic Atem Mini PROAI22/9/202517/6/2026
The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for controlling streaming, recording, formatting storage devices, and system reboot. This interface, referred to as the "ATEM Ethernet Protocol 1.0", provides complete device…
AnalizadaCrítica (9.8)0.53%—Blackmagicdesign WEB Presenter HD Firmware22/9/202517/6/2026
The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream…
AnalizadaCrítica (9.8)0.64%—Blackmagicdesign WEB Presenter HD FirmwareBlackmagicdesign WEB Presenter 4K Firmware22/9/202517/6/2026
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanisms are required to…
AnalizadaBaja (2.1)0.82%—Blackvuenorthamerica Blackvue Dr590x Firmware6/7/202517/6/2026
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local…
AnalizadaBaja (2.1)0.95%—Blackvuenorthamerica Blackvue Dr590x Firmware6/7/202517/6/2026
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within the local network.…
AnalizadaCrítica (9.8)0.73%—Blackberry QNX Software Development Platform10/6/202517/6/2026
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
AplazadaMedia (4.8)0.15%—Blackmagicdesign Davinci ResolveAI29/5/202517/6/2026
Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,…
AplazadaMedia (6.5)0.27%—Modernaweb Black Widgets FOR ElementorAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor black-widgets allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through <= 1.3.9.
AplazadaMedia (6.3)0.41%—Blackvue APPAI17/3/202517/6/2026
A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query strings. It is possible to initiate the attack remotely. The complexity of an…
AplazadaMedia (4.8)0.16%—Blackvue APPAI17/3/202517/6/2026
A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component API Endpoint Handler. The manipulation of the argument BCS_TOKEN/SECRET_KEY leads to unprotected storage of credentials. Local access is required to approach…
AplazadaBaja (2.5)0.16%—Carbonblack Cloud Windows SensorAI5/3/202517/6/2026
Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a vulnerability in software.
AplazadaAlta (7.1)0.15%—Blackbam Tinymce Advanced Qtranslate FIX Editor ProblemsAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-problems allows Stored XSS.This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through <= 1.0.0.
ModificadaMedia (6.1)0.15%—Blackandwhitedigital Bookpress7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.
ModificadaCrítica (9.8)0.47%—Blackandwhitedigital Bookpress7/2/202517/6/2026
Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.
AplazadaAlta (7.1)0.15%—Blackus3r WP Keyword MonitorAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in blackus3r WP Keyword Monitor wp-keyword-monitor allows Cross Site Request Forgery.This issue affects WP Keyword Monitor: from n/a through <= 1.0.5.
AplazadaAlta (7.1)0.20%—Wp-blackcheckAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stargazer WP-BlackCheck wp-blackcheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through <= 2.7.2.
AnalizadaAlta (7.5)0.57%—Blackberry QNX Software Development Platform14/1/202517/6/2026
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
AnalizadaAlta (7.5)0.44%—Blackberry QNX Software Development Platform14/1/202517/6/2026
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.