Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Aplazada | Media (4.3) | 0.19% | — | Blue CaptchaAI | 24/6/2026 | 25/6/2026 | The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from… | |
| Aplazada | Alta (8.1) | 0.34% | — | EcoblueAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions. | |
| Aplazada | Alta (8.1) | 0.56% | — | PHPAICodesupplyco BlueprintAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Bluetooth LEAI | 26/5/2026 | 23/7/2026 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. | |
| Aplazada | Media (6.5) | 0.43% | — | BigbluebuttonAI | 18/5/2026 | 24/7/2026 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been… | |
| Pendiente de análisis | Media (5.9) | 0.25% | — | Kaco BlueplanetAI | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3… | |
| Pendiente de análisis | Alta (7.2) | 0.19% | — | SMA Blueplanet 100 NX3 M8AISMA Blueplanet 100 TL3 Gen2AISMA Blueplanet 105 TL3AISMA Blueplanet 105 TL3 Gen2AI+26 | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-pdf-mcp-serverAI | 28/4/2026 | 24/7/2026 | A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-doc-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Aplazada | Media (6.5) | 0.30% | — | BigbluebuttonAI | 22/4/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available. | |
| Aplazada | Media (4.3) | 0.28% | — | BigbluebuttonAI | 22/4/2026 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available. | |
| Aplazada | Alta (8.1) | 0.37% | — | BlueprintueAI | 21/4/2026 | 17/6/2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid authenticated session — through XSS… | |
| Aplazada | Media (6.5) | 0.42% | — | BlueprintueAI | 21/4/2026 | 17/6/2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profile edit page, or when a password reset is completed via the reset link, neither operation invalidates existing authenticated sessions for that user. A server-side session store associates userID →… | |
| Aplazada | Alta (7.5) | 0.48% | — | BlueprintueAI | 21/4/2026 | 17/6/2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are processed at full network speed with no IP-based rate limiting, no per-account attempt counter, no temporary lockout, no progressive delay (Tarpit), and… | |
| Aplazada | Alta (7.4) | 0.32% | — | BlueprintueAI | 21/4/2026 | 17/6/2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-character CSPRNG token is generated and stored alongside a password_reset_at timestamp. However, the token redemption function findUserIDFromEmailAndToken() queries only for a matching email +… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Dynabook Bluetooth Acpi DriversAI | 13/4/2026 | 17/6/2026 | Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values. | |
| Analizada | Media (6.9) | 0.20% | — | Nsasoft Blueauditor | 12/4/2026 | 17/6/2026 | BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Priyanshumittal BluestreetAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3. | |
| Analizada | Baja (2.1) | 0.21% | — | Bluekitchen-gmbh Btstack | 30/3/2026 | 14/7/2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET_FOLDER_ITEMS handler that fails to validate packet boundaries and attribute count data. An attacker with a paired Bluetooth Classic connection can exploit insufficient bounds checking on the attr_id… | |
| Analizada | Baja (2.1) | 0.25% | — | Bluekitchen-gmbh Btstack | 30/3/2026 | 14/7/2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT and GET_PLAYER_APPLICATION_SETTING_VALUE_TEXT handlers that allows nearby attackers to read beyond packet boundaries. Attackers can establish a paired Bluetooth… | |
| Analizada | Baja (2.1) | 0.24% | — | Bluekitchen-gmbh Btstack | 30/3/2026 | 14/7/2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_ATTRIBUTES and LIST_PLAYER_APPLICATION_SETTING_VALUES handlers that allows attackers to read beyond buffer boundaries. A nearby attacker with a paired Bluetooth Classic… | |
| Aplazada | Alta (7.5) | 0.35% | — | Blueglass Jobs FOR WordpressAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jobs for WordPress: from n/a through <= 2.8. | |
| Analizada | Media (6.9) | 0.17% | — | Bluestacks | 21/3/2026 | 7/10/2026 | BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to the search field. Attackers can paste a buffer of 100,000 'A' characters into the search field and trigger a search operation to cause the application to crash. | |
| Analizada | Alta (8.1) | 0.36% | — | Bluewavelabs Checkmate | 20/3/2026 | 17/6/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to… |