Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.0%—Adobe Premiere Rush20/12/202117/6/2026
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaAlta (7.8)2.0%—Adobe Premiere Rush20/12/202117/6/2026
Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaMedia (5.5)2.8%—Adobe Premiere Rush26/6/202017/6/2026
Adobe Premiere Rush versions 1.5.8 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.8)4.5%—Adobe Premiere Rush25/6/202017/6/2026
Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)4.1%—Adobe Premiere Rush25/6/202017/6/2026
Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (7.8)6.2%—Adobe Premiere Rush25/6/202017/6/2026
Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution .
ModificadaAlta (8.1)1.0%—Titan SF Rush Smart Band Firmware22/4/202017/6/2026
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature…
ModificadaMedia (6.1)0.64%—Crushftp26/12/201917/6/2026
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
ModificadaAlta (8.1)1.7%—Pngcrush-installer Project Pngcrush-installer29/5/201817/6/2026
pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is…
ModificadaAlta (7.8)2.9%—Pngcrush Project Pngcrush6/10/201717/6/2026
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.
ModificadaCrítica (9.8)2.2%—Pngcrush Project Pngcrush31/8/201717/6/2026
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
ModificadaMedia (6.1)0.71%—Crushftp30/8/201717/6/2026
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
ModificadaMedia (6.1)0.71%—Crushftp30/8/201717/6/2026
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
ModificadaMedia (6.1)0.71%—Crushftp30/8/201717/6/2026
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
ModificadaCrítica (9.8)1.6%—Crushftp30/8/201717/6/2026
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
ModificadaMedia (5.4)0.27%—Tabtale Enchanted Fashion Crush19/10/201417/6/2026
The Enchanted Fashion Crush (aka com.tabtale.springcrushbundleint) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nexters Throne Rush3/10/201417/6/2026
The Throne Rush (aka com.progrestar.bft) application 2.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Miniclip Rail Rush9/9/201417/6/2026
The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.9)0.48%—GNU Rush8/5/201417/6/2026
GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
ModificadaBaja (2.1)0.31%—Elliot Pahl Drush Debian Packaging27/3/201316/6/2026
Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.
ModificadaAlta (9.3)1.5%—Ftprush20/8/201016/6/2026
Directory traversal vulnerability in IoRush Software FTP Rush 1.1.3 and possibly earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
ModificadaMedia (4.3)4.0%—Mcafee Intrushield Network Security Manager13/11/200916/6/2026
McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.
ModificadaMedia (4.3)2.2%—Mcafee Intrushield Network Security Manager13/11/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.
ModificadaAlta (7.5)2.0%—Ftprush27/12/200616/6/2026
Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. Also, it is not clear whether this issue crosses security boundaries.
ModificadaAlta (7.5)1.6%—Mcafee Intrushield Security Management System11/7/200516/6/2026
McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.