Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.9% | — | Elegantthemes Bloom | 20/9/2019 | 17/6/2026 | The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. | |
| Modificada | Alta (8.8) | 2.3% | — | Loom | 7/8/2019 | 17/6/2026 | Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application. The same attack vector can be used to… | |
| Modificada | Media (5.4) | 1.2% | — | Loomio | 24/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment. | |
| Modificada | Alta (7.5) | 6.9% | — | Oracle LinuxRedhat Enterprise LinuxBSD Mailx Project BSD MailxHeirloom Mailx | 24/12/2014 | 23/9/2026 | The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. | |
| Modificada | Media (5.4) | 0.27% | — | Bloomyou Valentine | 19/10/2014 | 17/6/2026 | The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Parentlink Bloom Township 206 | 29/9/2014 | 17/6/2026 | The Bloom Township 206 (aka net.parentlink.bloom) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.6) | 2.3% | — | Studio Achtundachtzig Bloomooweb Activex Control | 3/11/2006 | 16/6/2026 | BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path… | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Loom Software Surfnow ProfessionalLoom Software Surfnow Standard | 31/12/2004 | 16/6/2026 | SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. |