Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)66%💥 ExploitBluecoat WebproxyBluecoat Proxyav31/12/200516/6/2026
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.
ModificadaMedia (6.4)4.8%💥 ExploitAnycom Blue Usb-130-250 SoftwareBelkin Bluetooth SoftwareWidcomm Bluetooth FOR Windows20/12/200516/6/2026
The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send…
ModificadaAlta (7.5)1.1%—Bluewhalecrm8/9/200516/6/2026
SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.
ModificadaAlta (7.5)2.4%—Bluez Project Bluez12/8/200516/6/2026
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.
ModificadaMedia (5)7.5%💥 ExploitBlue-collar Productions I-gallery20/6/200516/6/2026
Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.
ModificadaMedia (4.3)0.94%—Blue-collar Productions I-gallery20/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
ModificadaMedia (4.6)1.2%💥 ExploitBluecoat Reporter24/5/200516/6/2026
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.
ModificadaMedia (4.3)1.3%—Bluecoat Reporter24/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.
ModificadaAlta (7.5)2.8%💥 ExploitBluecoat Reporter24/5/200516/6/2026
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.
ModificadaMedia (5)2.4%💥 ExploitIVT Bluesoleil2/5/200516/6/2026
Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.
ModificadaAlta (7.5)60%💥 ExploitWorking Resources Inc. Badblue2/5/200516/6/2026
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
ModificadaMedia (5)2.8%💥 ExploitWorking Resources Inc. Badblue31/12/200416/6/2026
BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
ModificadaAlta (7.5)0.86%—Broadcom Bluecoat Security Gateway31/12/200416/6/2026
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.
ModificadaMedia (5)7.2%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS.
ModificadaAlta (7.5)9.5%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo.
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio.
ModificadaAlta (7.5)3.6%—Widcomm Bluetooth Communication SoftwareWidcomm Btstackserver20/10/200416/6/2026
Desbordamiento de búfer en WIDCOMM Bluetooth Connectivity Software, usado en productos como BTStackServer 1.3.2.7 y 1.4.2.10, Windows XP y Windows 98 con mochilas Bluetooth MSI, y HP IPAQ 5450 con WinCE 3.0, permite a atacantes remotos ejecutar código de su elección mediante ciertas peticiones de servicio.
ModificadaMedia (5)3.1%💥 ExploitWorking Resources Inc. Badblue20/8/200416/6/2026
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.
ModificadaAlta (7.6)7.0%💥 ExploitWorking Resources Inc. Badblue9/6/200316/6/2026
La extendisón ISAPI en BadBlue 1.7 hasta 2.2, y posiblemente versiones anteriores, modifica las dos primeras letras de la extensión de un archivo después de realizar comprobaciones de seguridad, lo que permite que atacantes remotos pasen la autentificación mediante un fichero .ats en lugar de uno .hts.
ModificadaAlta (7.5)1.5%—Working Resources Inc. Badblue31/3/200316/6/2026
BadBlue 1.7 permiten a atacantes remotos eludir las protecciones de contraseñas en directorios y ficheros mediante una petición HTTP que contiene un caracter / (slash).
ModificadaAlta (7.5)4.7%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the…
ModificadaAlta (7.5)40%💥 ExploitMicrosoft Foundation Class LibraryWorking Resources Inc. Badblue31/12/200216/6/2026
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and…
ModificadaMedia (5)1.4%—Working Resources Inc. Badblue31/12/200216/6/2026
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
ModificadaMedia (5)4.9%—Deerfield D2gfxWorking Resources Inc. Badblue31/12/200216/6/2026
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.
ModificadaMedia (4.3)1.7%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.