Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Intel Thunderbolt DCH Driver | 12/11/2020 | 17/6/2026 | Protection mechanism failure in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.99% | — | Boltbrowser Bolt Browser | 20/10/2020 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Bolt Browser version 1.4 and prior versions. | |
| Modificada | Media (4.6) | 0.34% | — | Intel Dsl3310 Thunderbolt FirmwareIntel Dsl3510 Thunderbolt FirmwareIntel Dsl4510 Thunderbolt FirmwareIntel Dsl4410 Thunderbolt Firmware+9 | 13/8/2020 | 17/6/2026 | Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access. | |
| Modificada | Media (6.1) | 2.0% | — | Boltcms Bolt | 8/6/2020 | 17/6/2026 | In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, once created/uploaded, it can be renamed to inject the payload in it. Additionally, the measures to prevent renaming the… | |
| Modificada | Media (4.3) | 1.8% | 💥 PoC | Boltcms Bolt | 8/6/2020 | 17/6/2026 | Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a… | |
| Modificada | Media (6) | 0.26% | — | Dell Dock Wd15 FirmwareDell Dock Wd19 FirmwareDell Thunderbolt Dock Tb16 FirmwareDell Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware | 28/5/2020 | 17/6/2026 | Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally… | |
| Modificada | Media (6.1) | 0.88% | — | Boltwire | 2/1/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Boltcms Bolt | 31/12/2019 | 17/6/2026 | Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933. | |
| Modificada | Media (6.1) | 0.70% | — | Boltcms Bolt | 29/12/2019 | 17/6/2026 | Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040 | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via an image's alt or title field. | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via a title that is mishandled in the system log. | |
| Modificada | Alta (8.8) | 4.5% | 💥 Exploit | Boltcms Bolt | 5/4/2019 | 17/6/2026 | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file. | |
| Modificada | Alta (8.8) | 2.7% | — | Boltcms Bolt | 7/3/2019 | 17/6/2026 | Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension. | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Bolt CMS | 17/12/2018 | 17/6/2026 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry. | |
| Modificada | Media (5.4) | 0.52% | — | Passbolt API | 2/1/2018 | 17/6/2026 | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | |
| Modificada | Media (5.3) | 1.8% | — | Boltcms Bolt | 10/11/2017 | 17/6/2026 | Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php. | |
| Modificada | Media (5.4) | 0.55% | — | Boltcms Bolt | 17/7/2017 | 17/6/2026 | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. | |
| Modificada | Media (5.4) | 0.55% | — | Boltcms Bolt | 17/7/2017 | 17/6/2026 | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header. | |
| Modificada | Media (6.5) | 39% | 💥 Exploit | Boltcms Bolt | 22/9/2015 | 17/6/2026 | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it. | |
| Modificada | Media (4.3) | 2.1% | — | Boltwire | 23/10/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php. | |
| Modificada | Baja (2.6) | 1.3% | — | HTC Desire HDHTC Desire SHTC Droid IncredibleHTC EVO 3D+5 | 5/2/2012 | 16/6/2026 | Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that… | |
| Modificada | Baja (2.6) | 1.0% | — | Google AndroidHTC EVO 3DHTC EVO 4GHTC Thunderbolt | 3/10/2011 | 16/6/2026 | A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive… | |
| Modificada | Alta (9.3) | 1.8% | — | Xunlei WEB Thunderbolt | 20/6/2007 | 16/6/2026 | The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by invoking dangerous methods. | |
| Modificada | Alta (10) | 6.0% | — | Bolthole Filter | 10/1/2005 | 16/6/2026 | Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message. |