Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Adobe Premiere PRO | 21/10/2020 | 17/6/2026 | Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 2.8% | — | Adobe Premiere Rush | 26/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.8 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 2.7% | — | Adobe Premiere PRO | 26/6/2020 | 17/6/2026 | Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.8) | 4.5% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 4.1% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 6.2% | — | Adobe Premiere Rush | 25/6/2020 | 17/6/2026 | Adobe Premiere Rush versions 1.5.12 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 2.1% | — | Adobe Premiere PRO | 25/6/2020 | 17/6/2026 | Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 2.2% | — | Adobe Premiere PRO | 25/6/2020 | 17/6/2026 | Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 2.4% | — | Adobe Premiere PRO | 25/6/2020 | 17/6/2026 | Adobe Premiere Pro versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 3.1% | — | Adobe Premiere PRO CC | 14/8/2019 | 17/6/2026 | Adobe Premiere Pro CC versions 13.1.2 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (5.3) | 0.92% | — | IBM Kenexa Lcms Premier | 27/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Kenexa Lcms Premier | 27/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and… | |
| Modificada | Media (6.7) | 0.53% | — | Avast Free AntivirusAvast Internet SecurityAvast PremierAvast PRO Antivirus | 21/3/2017 | 17/6/2026 | Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Avast process via a… | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805. | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067. | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067. | |
| Modificada | Alta (8.8) | 1.4% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 0.99% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user. | |
| Modificada | Media (4.3) | 1.3% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Modificada | Media (5.5) | 0.40% | — | Avast Business SecurityAvast Free AntivirusAvast Internet SecurityAvast Premier+7 | 3/11/2016 | 17/6/2026 | Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x… | |
| Modificada | Alta (7.8) | 0.50% | — | Avast Free AntivirusAvast Internet SecurityAvast PremierAvast PRO Antivirus | 13/4/2016 | 17/6/2026 | Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request. | |
| Modificada | Alta (10) | 4.2% | — | Adobe Premiere Clip | 18/11/2015 | 17/6/2026 | The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors. |