Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.50% | — | Crushftp | 14/5/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Crushftp | 22/4/2024 | 17/6/2026 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server. | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Crítica (9.8) | 82% | — | Crushftp | 18/11/2023 | 17/6/2026 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | |
| Modificada | Alta (7.8) | 0.36% | — | Adobe Premiere Rush | 17/2/2023 | 17/6/2026 | Adobe Premiere Rush version 2.6 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.40% | — | Adobe Premiere Rush | 17/2/2023 | 17/6/2026 | Adobe Premiere Rush version 2.6 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.4) | 0.57% | — | Rushstreetinteractive Rushbet | 18/1/2023 | 17/6/2026 | RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives. | |
| Modificada | Alta (8.8) | 0.32% | — | Keywordrush Content EGG | 3/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. | |
| Modificada | Media (4.8) | 0.68% | — | Crushftp | 15/9/2022 | 17/6/2026 | An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in… | |
| Modificada | Media (6.1) | 0.80% | — | Keywordrush Content EGG | 2/5/2022 | 17/6/2026 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.5) | 1.9% | — | Adobe Premiere Rush | 16/2/2022 | 17/6/2026 | Adobe Premiere Rush versions 2.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Media (5.5) | 1.4% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim… | |
| Modificada | Media (5.5) | 1.4% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim… | |
| Modificada | Media (5.5) | 1.4% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim… | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Media (5.5) | 1.7% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose sensitive information on affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Modificada | Baja (3.3) | 1.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows remote attackers to disclose arbitrary data on affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EPS/TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PNG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. |