Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.37% | — | Mailscanner | 28/10/2019 | 16/6/2026 | mailscanner can allow local users to prevent virus signatures from being updated | |
| Modificada | Media (5.5) | 0.25% | — | Jenkins Neuvector Vulnerability Scanner | 25/9/2019 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Alta (7.5) | 0.89% | — | Jenkins Aqua Security Scanner | 25/9/2019 | 17/6/2026 | Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (5.3) | 0.77% | — | Jenkins Aqua Microscanner | 25/9/2019 | 17/6/2026 | Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Baja (3.1) | 0.59% | — | Jenkins Aqua Security Severless Scanner | 12/9/2019 | 17/6/2026 | Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. | |
| Modificada | Alta (8.8) | 1.8% | — | Jenkins Aqua Microscanner | 30/4/2019 | 17/6/2026 | Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Cp5525 FirmwareHP Color Laserjet Enterprise M553 FirmwareHP Color Laserjet Enterprise M552 Firmware+139 | 11/4/2019 | 17/6/2026 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Veracode-scanner | 4/4/2019 | 17/6/2026 | Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Aqua Security Scanner | 4/4/2019 | 17/6/2026 | Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+134 | 27/3/2019 | 17/6/2026 | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code. | |
| Modificada | Alta (7.8) | 0.34% | — | Sonarsource Sonarqube Scanner | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube. | |
| Modificada | Media (6.5) | 0.87% | — | Anchore Container Image Scanner | 1/8/2018 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration. | |
| Modificada | Alta (7.8) | 2.5% | — | F-secure Online Scanner | 2/8/2017 | 17/6/2026 | Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe. | |
| Modificada | Media (5.5) | 1.8% | — | Acunetix WEB Vulnerability Scanner | 27/7/2017 | 17/6/2026 | Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess." | |
| Modificada | Crítica (9.8) | 2.7% | — | Acunetix WEB Vulnerability Scanner | 27/7/2017 | 17/6/2026 | Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Write AV starting at reporter!madTraceProcess." | |
| Modificada | Media (5.9) | 0.49% | — | Yottamark Inc. Shopwell - Healthy Diet & Grocery Food Scanner | 15/5/2017 | 17/6/2026 | The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Acunetix WEB Vulnerability Scanner | 17/12/2015 | 17/6/2026 | The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan. | |
| Modificada | Alta (7.2) | 0.48% | — | Motorola Scanner SDK | 16/2/2015 | 17/6/2026 | Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 3.3% | — | Motorola Scanner SDK | 16/2/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx. | |
| Modificada | Media (4.3) | 1.1% | — | IPA Ilogscanner | 15/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggering a crafted entry in a log file. | |
| Modificada | Media (5.4) | 0.27% | — | Barcode Scanner Project Barcode Scanner | 2/10/2014 | 17/6/2026 | The barcode scanner (aka tw.com.books.android.plus) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Intsig Camscanner -phone PDF Creator | 9/9/2014 | 17/6/2026 | The CamScanner -Phone PDF Creator (aka com.intsig.camscanner) application 3.4.0.20140624 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 26% | 💥 Exploit | Acunetix WEB Vulnerability Scanner | 27/4/2014 | 17/6/2026 | Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute). | |
| Modificada | Media (4.3) | 98% | — | Ahnlab V3 Internet SecurityAladdin EsafeAVG Anti-virusCAT Quick Heal+6 | 21/3/2012 | 16/6/2026 | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus… | |
| Modificada | Media (4.3) | 92% | — | Anti-virus Vba32Authentium Command AntivirusAVG Anti-virusBitdefender+16 | 21/3/2012 | 16/6/2026 | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky… |