Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.21% | — | Backblaze B2 Command Line Tool | 23/2/2022 | 17/6/2026 | B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU)… | |
| Modificada | Media (4.7) | 0.22% | — | Backblaze B2 Python Software Development KIT | 23/2/2022 | 17/6/2026 | b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of… | |
| Modificada | Alta (7.5) | 2.1% | — | Typelevel Blaze | 2/2/2021 | 17/6/2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are affected by a vulnerability in which unbounded connection acceptance leads to file handle exhaustion. Blaze, accepts connections unconditionally on a dedicated thread… | |
| Modificada | Alta (7.8) | 0.59% | — | Backblaze | 27/12/2020 | 17/6/2026 | Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary. | |
| Modificada | Alta (7.8) | 4.7% | — | Backblaze | 27/12/2020 | 17/6/2026 | Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality. | |
| Modificada | Crítica (9.8) | 21% | — | Apache Flex BlazedsHP XP Command View Advanced Edition | 28/12/2017 | 17/6/2026 | Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One… | |
| Modificada | Media (5) | 3.8% | — | Adobe BlazedsAdobe Livecycle Data ServicesAdobe Livecycle | 16/6/2011 | 16/6/2026 | Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object graph vulnerability." | |
| Modificada | Alta (10) | 6.1% | — | Adobe BlazedsAdobe Livecycle Data ServicesAdobe Livecycle | 16/6/2011 | 16/6/2026 | Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization… | |
| Analizada | Media (6.5) | 90% | ⚠ Explotación activa | Adobe BlazedsAdobe ColdfusionAdobe Flex Data ServicesAdobe Livecycle+1 | 15/2/2010 | 6/8/2026 | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request,… | |
| Modificada | Alta (9.3) | 10% | — | Blazevideo Hdtv Player | 10/2/2009 | 16/6/2026 | Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file. | |
| Modificada | Alta (9.3) | 36% | — | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.5) | 4.9% | — | Blazevideo Hdtv Player | 8/12/2006 | 16/6/2026 | Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199. NOTE: it was later reported that 3.5 is also affected. | |
| Modificada | Alta (7.5) | 65% | — | Blazevideo Blaze DVD | 1/12/2006 | 16/6/2026 | Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist. | |
| Modificada | Baja (2.1) | 0.36% | — | Matt Blaze Cryptographic File System | 7/8/2006 | 16/6/2026 | Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb. | |
| Modificada | Media (4.3) | 2.2% | — | Outblaze | 7/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in throw.main in Outblaze allows remote attackers to inject arbitrary web script or HTML via the file parameter. | |
| Modificada | Media (5.1) | 2.6% | — | Outblaze Email | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag. | |
| Modificada | Alta (7.5) | 4.1% | — | Matt Blaze CFS | 25/6/2002 | 16/6/2026 | Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code. |