Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.3% | — | Raspberrypi Raspberry PI 3 Model B+ Firmware | 4/4/2019 | 17/6/2026 | The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging. With a debug host processor A running in non-secure EL1 and a debug target processor B… | |
| Modificada | Media (5.9) | 2.3% | 💥 PoC | Blackberry Athoc | 21/3/2019 | 17/6/2026 | An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing… | |
| Modificada | Alta (7.5) | 3.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+14 | 19/2/2019 | 17/6/2026 | Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. | |
| Modificada | Alta (7.5) | 2.6% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+11 | 19/2/2019 | 17/6/2026 | Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. | |
| Modificada | Crítica (9.8) | 1.3% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+8 | 29/1/2019 | 17/6/2026 | In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials. | |
| Modificada | Media (6.5) | 0.41% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator. | |
| Modificada | Media (4.8) | 0.51% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator. | |
| Modificada | Media (4.8) | 0.51% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator. | |
| Modificada | Alta (7.5) | 1.1% | — | Blackberry Unified Endpoint Manager | 12/10/2018 | 17/6/2026 | An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user. | |
| Modificada | Media (4.7) | 0.48% | — | Blackberry Enterprise Mobility Server | 19/9/2018 | 17/6/2026 | A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account. | |
| Modificada | Media (6.1) | 0.91% | — | Blackberry Unified Endpoint Manager | 13/3/2018 | 17/6/2026 | In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the… | |
| Modificada | Alta (7.8) | 0.56% | — | Linux KernelDebian LinuxOpensuse LeapOpensuse Project Leap+4 | 20/12/2017 | 17/6/2026 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a… | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxOpensuse LeapOpensuse Project Leap+4 | 20/12/2017 | 17/6/2026 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified… | |
| Modificada | Baja (2.6) | 0.81% | — | Blackberry QNX Software Development Platform | 14/11/2017 | 17/6/2026 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental… | |
| Modificada | Baja (3.8) | 0.56% | — | Blackberry QNX Software Development Platform | 14/11/2017 | 17/6/2026 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout of higher privileged processes by manipulating environment variables that… | |
| Modificada | Baja (1.9) | 0.50% | — | Blackberry QNX Software Development Platform | 14/11/2017 | 17/6/2026 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks. | |
| Modificada | Baja (3.8) | 0.78% | — | Blackberry QNX Software Development Platform | 14/11/2017 | 17/6/2026 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout that could be used in a blended attack by executing commands targeting procfs resources. | |
| Modificada | Crítica (9.6) | 1.3% | — | Blackberry QNX Software Development Platform | 14/11/2017 | 17/6/2026 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take ownership of files on other QNX nodes… | |
| Modificada | Alta (7.5) | 1.4% | — | Blackberry Workspaces VappBlackberry Workspaces Appliance-x | 16/10/2017 | 17/6/2026 | An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files. | |
| Modificada | Crítica (9.8) | 1.6% | — | Blackberry Workspaces VappBlackberry Workspaces Appliance-x | 16/10/2017 | 17/6/2026 | A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request. | |
| Modificada | Alta (8.8) | 0.86% | — | Blackberry Workspaces | 9/8/2017 | 17/6/2026 | An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server. | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+16 | 19/6/2017 | 17/6/2026 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these… | |
| Modificada | Media (6.1) | 0.85% | — | Blackberry Enterprise ServiceBlackberry Unified Endpoint Manager | 10/5/2017 | 17/6/2026 | A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target… | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Blackberry Enterprise Service | 13/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp. | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Blackberry Enterprise Service | 13/4/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3)… |