Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.7%—Fireblink Object-collider1/3/202117/6/2026
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)3.8%—Amazon Blink XT2 Sync Module Firmware31/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
ModificadaCrítica (9.8)3.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.
ModificadaAlta (8.8)1.2%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.
ModificadaAlta (8.8)1.7%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.
ModificadaMedia (6.8)1.0%—Amazon Blink XT2 Sync Module Firmware11/12/201917/6/2026
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.
ModificadaMedia (6.5)0.47%—Google Blink12/11/201916/6/2026
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
ModificadaMedia (6.5)0.62%—Google Blink12/11/201916/6/2026
WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).
ModificadaMedia (6.5)0.47%—Google Blink12/11/201916/6/2026
Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections.
ModificadaAlta (7.5)0.60%—Google Blink12/11/201916/6/2026
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
ModificadaCrítica (9.8)0.81%—Google Blink7/11/201916/6/2026
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
ModificadaMedia (6.5)0.60%—Google Blink7/11/201916/6/2026
An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.
ModificadaMedia (6.5)0.47%—Google Blink7/11/201916/6/2026
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
ModificadaMedia (6.5)0.68%—Google Blink7/11/201916/6/2026
Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.
ModificadaMedia (6.5)0.97%—Google Blink6/11/201916/6/2026
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
ModificadaAlta (7.5)0.86%—Google Blink6/11/201916/6/2026
An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect function.
ModificadaCrítica (9.8)0.91%—Google Blink5/11/201916/6/2026
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
ModificadaMedia (6.5)0.65%—Google Blink5/11/201916/6/2026
The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.
ModificadaMedia (6.5)0.74%—Blinkforhome Sync Module15/12/201817/6/2026
A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network.…
ModificadaMedia (4.3)1.9%—Allomani Weblinks4/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.
ModificadaMedia (5.4)0.27%—Chemssou Blink Project Chemssou Blink21/10/201417/6/2026
The Chemssou Blink (aka com.chemssou.blink) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.1%—Allomani Weblinks14/10/201417/6/2026
Multiple SQL injection vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in a browse action to index.php or (2) unspecified parameters to admin.php.
ModificadaMedia (5)2.4%—Blinkwebeffects Social-media-widget25/4/201316/6/2026
Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.
Orbitaley — Vulnerabilidades