Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.0% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 2.0% | — | Adobe Premiere Rush | 20/12/2021 | 17/6/2026 | Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Media (5.5) | 2.8% | — | Adobe Premiere Rush | 26/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.8 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.8) | 4.5% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 4.1% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 6.2% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (8.1) | 1.0% | — | Titan SF Rush Smart Band Firmware | 22/4/2020 | 17/6/2026 | An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature… | |
| Modificada | Media (6.1) | 0.64% | — | Crushftp | 26/12/2019 | 17/6/2026 | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection. | |
| Modificada | Alta (8.1) | 1.7% | — | Pngcrush-installer Project Pngcrush-installer | 29/5/2018 | 17/6/2026 | pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is… | |
| Modificada | Alta (7.8) | 2.9% | — | Pngcrush Project Pngcrush | 6/10/2017 | 17/6/2026 | Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file. | |
| Modificada | Crítica (9.8) | 2.2% | — | Pngcrush Project Pngcrush | 31/8/2017 | 17/6/2026 | Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (6.1) | 0.71% | — | Crushftp | 30/8/2017 | 17/6/2026 | CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability. | |
| Modificada | Media (6.1) | 0.71% | — | Crushftp | 30/8/2017 | 17/6/2026 | CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability. | |
| Modificada | Media (6.1) | 0.71% | — | Crushftp | 30/8/2017 | 17/6/2026 | CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS. | |
| Modificada | Crítica (9.8) | 1.6% | — | Crushftp | 30/8/2017 | 17/6/2026 | CrushFTP 8.x before 8.2.0 has a serialization vulnerability. | |
| Modificada | Media (5.4) | 0.27% | — | Tabtale Enchanted Fashion Crush | 19/10/2014 | 17/6/2026 | The Enchanted Fashion Crush (aka com.tabtale.springcrushbundleint) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nexters Throne Rush | 3/10/2014 | 17/6/2026 | The Throne Rush (aka com.progrestar.bft) application 2.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Miniclip Rail Rush | 9/9/2014 | 17/6/2026 | The Rail Rush (aka com.miniclip.railrush) application 1.9.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.9) | 0.48% | — | GNU Rush | 8/5/2014 | 17/6/2026 | GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option. | |
| Modificada | Baja (2.1) | 0.31% | — | Elliot Pahl Drush Debian Packaging | 27/3/2013 | 16/6/2026 | Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors. | |
| Modificada | Alta (9.3) | 1.5% | — | Ftprush | 20/8/2010 | 16/6/2026 | Directory traversal vulnerability in IoRush Software FTP Rush 1.1.3 and possibly earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename. | |
| Modificada | Media (4.3) | 4.0% | — | Mcafee Intrushield Network Security Manager | 13/11/2009 | 16/6/2026 | McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (4.3) | 2.2% | — | Mcafee Intrushield Network Security Manager | 13/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Ftprush | 27/12/2006 | 16/6/2026 | Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. Also, it is not clear whether this issue crosses security boundaries. | |
| Modificada | Alta (7.5) | 1.6% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack. |