Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.7% | — | Fireblink Object-collider | 1/3/2021 | 17/6/2026 | Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 3.8% | — | Amazon Blink XT2 Sync Module Firmware | 31/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. | |
| Modificada | Crítica (9.8) | 3.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter. | |
| Modificada | Media (6.8) | 1.0% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. | |
| Modificada | Media (6.5) | 0.47% | — | Google Blink | 12/11/2019 | 16/6/2026 | An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element. | |
| Modificada | Media (6.5) | 0.62% | — | Google Blink | 12/11/2019 | 16/6/2026 | WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption). | |
| Modificada | Media (6.5) | 0.47% | — | Google Blink | 12/11/2019 | 16/6/2026 | Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections. | |
| Modificada | Alta (7.5) | 0.60% | — | Google Blink | 12/11/2019 | 16/6/2026 | A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function. | |
| Modificada | Crítica (9.8) | 0.81% | — | Google Blink | 7/11/2019 | 16/6/2026 | A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms. | |
| Modificada | Media (6.5) | 0.60% | — | Google Blink | 7/11/2019 | 16/6/2026 | An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts. | |
| Modificada | Media (6.5) | 0.47% | — | Google Blink | 7/11/2019 | 16/6/2026 | Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13. | |
| Modificada | Media (6.5) | 0.68% | — | Google Blink | 7/11/2019 | 16/6/2026 | Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function. | |
| Modificada | Media (6.5) | 0.97% | — | Google Blink | 6/11/2019 | 16/6/2026 | A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed. | |
| Modificada | Alta (7.5) | 0.86% | — | Google Blink | 6/11/2019 | 16/6/2026 | An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect function. | |
| Modificada | Crítica (9.8) | 0.91% | — | Google Blink | 5/11/2019 | 16/6/2026 | WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks. | |
| Modificada | Media (6.5) | 0.65% | — | Google Blink | 5/11/2019 | 16/6/2026 | The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin. | |
| Modificada | Media (6.5) | 0.74% | — | Blinkforhome Sync Module | 15/12/2018 | 17/6/2026 | A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network.… | |
| Modificada | Media (4.3) | 1.9% | — | Allomani Weblinks | 4/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php. | |
| Modificada | Media (5.4) | 0.27% | — | Chemssou Blink Project Chemssou Blink | 21/10/2014 | 17/6/2026 | The Chemssou Blink (aka com.chemssou.blink) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Allomani Weblinks | 14/10/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in a browse action to index.php or (2) unspecified parameters to admin.php. | |
| Modificada | Media (5) | 2.4% | — | Blinkwebeffects Social-media-widget | 25/4/2013 | 16/6/2026 | Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files. |