Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.79%—Blackberry Unified Endpoint Management13/5/202117/6/2026
An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially gain access to a victim's web history.
ModificadaAlta (7.3)0.96%—Blackberry Unified Endpoint Management13/5/202117/6/2026
A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user.
ModificadaMedia (5.5)0.22%—Blackberry Unified Endpoint Management13/5/202117/6/2026
A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially to prevent any new user connections.
ModificadaAlta (8.8)0.96%—Blackberry Workspaces Server13/5/202117/6/2026
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account.
ModificadaMedia (5.5)0.27%—Blackberry Unified Endpoint Manager14/10/202017/6/2026
An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service.
ModificadaCrítica (9.8)3.6%—Blackberry QNX Software Development Platform12/8/202017/6/2026
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
AnalizadaMedia (6.5)86%⚠ Explotación activa💥 ExploitSaltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+230/4/202017/6/2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitApache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+1724/2/202025/8/2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.…
ModificadaMedia (6.5)2.1%—Blackberry Playbook Firmware10/2/202016/6/2026
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
ModificadaAlta (7.8)0.22%—Blackberry QNX Software Development Platform12/7/201917/6/2026
An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attacker to potentially gain unauthorized access to a chosen process address space.
ModificadaAlta (7.5)1.5%—Blackberry Unified Endpoint Management18/4/201917/6/2026
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
ModificadaMedia (5.9)2.3%💥 PoCBlackberry Athoc21/3/201917/6/2026
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing…
ModificadaMedia (6.5)0.41%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.
ModificadaMedia (4.8)0.51%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
ModificadaMedia (4.8)0.51%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
ModificadaAlta (7.5)1.1%—Blackberry Unified Endpoint Manager12/10/201817/6/2026
An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user.
ModificadaMedia (4.7)0.48%—Blackberry Enterprise Mobility Server19/9/201817/6/2026
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
ModificadaMedia (6.1)0.91%—Blackberry Unified Endpoint Manager13/3/201817/6/2026
In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the…
ModificadaBaja (2.6)0.81%—Blackberry QNX Software Development Platform14/11/201717/6/2026
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental…
ModificadaBaja (3.8)0.56%—Blackberry QNX Software Development Platform14/11/201717/6/2026
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout of higher privileged processes by manipulating environment variables that…
ModificadaBaja (1.9)0.50%—Blackberry QNX Software Development Platform14/11/201717/6/2026
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.
ModificadaBaja (3.8)0.78%—Blackberry QNX Software Development Platform14/11/201717/6/2026
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout that could be used in a blended attack by executing commands targeting procfs resources.
ModificadaCrítica (9.6)1.3%—Blackberry QNX Software Development Platform14/11/201717/6/2026
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes…
ModificadaAlta (7.5)1.4%—Blackberry Workspaces VappBlackberry Workspaces Appliance-x16/10/201717/6/2026
An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.
ModificadaCrítica (9.8)1.6%—Blackberry Workspaces VappBlackberry Workspaces Appliance-x16/10/201717/6/2026
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
Orbitaley — Vulnerabilidades