Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2395 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)3.6%—Adobe Flash PlayerAdobe Flash Player Desktop RuntimeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+113/12/201717/6/2026
A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data.
ModificadaCrítica (9.8)6.2%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/12/201717/6/2026
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid…
ModificadaCrítica (9.8)6.2%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/12/201717/6/2026
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal…
ModificadaCrítica (9.8)6.1%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/12/201717/6/2026
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to…
ModificadaCrítica (9.8)6.1%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/12/201717/6/2026
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption,…
ModificadaCrítica (9.8)6.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/12/201717/6/2026
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque…
ModificadaCrítica (9.8)34%💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation1/12/201717/6/2026
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
ModificadaCrítica (9.8)34%💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation1/12/201717/6/2026
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
ModificadaMedia (5.5)3.2%💥 ExploitKmplayer28/11/201717/6/2026
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
ModificadaBaja (2.5)6.7%—Microsoft Windows Media Player15/11/201717/6/2026
Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows remote attackers to test for the presence of files on disk via a specially crafted…
AnalizadaAlta (8.8)12%⚠ Explotación activaAdobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+122/10/201717/6/2026
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)3.1%💥 ExploitTecnovision DLX Spot Player421/9/201717/6/2026
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
ModificadaAlta (8.8)10%💥 ExploitTecnovision DLX Spot Player421/9/201717/6/2026
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
ModificadaCrítica (9.8)2.9%—Tecnovision DLX Spot Player421/9/201717/6/2026
A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges to root access with the same credentials.
ModificadaAlta (8.8)22%💥 ExploitRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux WorkstationAdobe Flash Player Desktop Runtime+111/8/201717/6/2026
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.4)4.5%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+111/8/201717/6/2026
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
ModificadaAlta (7.8)0.83%—Softonic Spider Player30/7/201717/6/2026
VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file.
ModificadaMedia (6.5)3.7%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure.
ModificadaAlta (8.8)8.6%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (6.5)4.2%—Adobe Flash Player Desktop RuntimeAdobe Flash Player17/7/201717/6/2026
Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure.
ModificadaCrítica (9.8)4.5%—Videolan VLC Media Player30/6/201717/6/2026
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
ModificadaCrítica (9.8)5.2%—Adobe Flash PlayerAdobe Flash Player Extended Support ReleaseAdobe Flash Player FOR LinuxAdobe AIR+227/6/201717/6/2026
Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet…
ModificadaAlta (7.8)1.6%—Cisco Webex Advanced Recording Format Player26/6/201717/6/2026
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious ARF file via email or URL and convincing the user to launch the file. Exploitation of these…
ModificadaCrítica (9.8)6.9%—Adobe Shockwave Player20/6/201717/6/2026
Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)8.7%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.
Orbitaley — Vulnerabilidades