Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.62%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
AnalizadaAlta (8.1)0.46%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.
AnalizadaMedia (5.3)0.55%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.
AnalizadaAlta (7.5)0.71%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.
AnalizadaAlta (7.5)0.75%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.
AnalizadaAlta (7.5)0.75%—Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+31625/10/202417/6/2026
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.
AplazadaAlta (8.7)0.37%—Messagepack-csharpAI17/10/202417/6/2026
### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consumption disproportionate to the size of the data being deserialized. This is similar…
AplazadaMedia (6.5)0.32%—Sharp NEC ProjectorAI27/9/202417/6/2026
Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W,…
AnalizadaAlta (7.8)0.32%—Restsharp29/8/202417/6/2026
RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a request is via the…
AnalizadaMedia (6.4)0.26%—Doublesharp Remote Content Shortcode1/8/202417/6/2026
The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating…
ModificadaAlta (7.5)0.77%—Sixlabors Imagesharp22/7/202417/6/2026
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users…
ModificadaAlta (7.5)0.67%—Sixlabors Imagesharp22/7/202417/6/2026
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.
AplazadaMedia (5.9)0.26%—Hans VAN Eijsden Imagemagick Sharpen Resized ImagesAI3/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue affects ImageMagick Sharpen Resized Images: from n/a through 1.1.7.
AplazadaMedia (5.4)0.27%—Doublesharp Remote Content ShortcodeAI30/5/202417/6/2026
The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
AplazadaMedia (6.1)0.25%—Pointsharp Cryptshare ServerAI27/5/202417/6/2026
Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.
AplazadaMedia (6.5)0.59%—Doublesharp Remote Content ShortcodeAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.
AplazadaAlta (7.5)1.1%—Bouncycastle BC JavaAIBouncycastle BC Java LTSAIBouncycastle BC FJAAIBouncycastle BC C Sharp NETAI14/5/202417/6/2026
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
AplazadaMedia (4.3)0.35%—Sharp Rouvo VAI22/4/202417/6/2026
A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that can be accessed by any local app on the device without any permissions or special privileges.…
AplazadaBaja (3.4)0.16%—BLU View 2AIBoost Mobile Celero 5GAISharp Rouvo VAIMotorola Moto G PureAI+322/4/202417/6/2026
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl 6 Pro 5G, and T-Mobile Revvl V+ 5G…
AplazadaAlta (7.8)0.19%—BLU View 2AISharp Rouvo VAI22/4/202417/6/2026
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode='9020801', versionName='9.0208.01' ; versionCode='9020913', versionName='9.0209.13' ; versionCode='9021203', versionName='9.0212.03') that allows…
AnalizadaMedia (6.5)0.57%—Sixlabors Imagesharp15/4/202417/6/2026
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the…
AnalizadaMedia (6.5)0.63%—Sixlabors Imagesharp15/4/202417/6/2026
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in image decoders. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. This flaw…
AnalizadaAlta (7.1)0.35%—Sixlabors Imagesharp5/3/202417/6/2026
ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to…
AnalizadaAlta (8.8)1.2%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.
ModificadaAlta (8.1)0.81%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.