Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.9) | 0.10% | — | Bluestacks | 5/8/2025 | 5/7/2026 | A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information. | |
| Aplazada | Alta (8.8) | 11% | — | Airoha Bluetooth Audio SDKAI | 4/8/2025 | 17/6/2026 | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Aplazada | Alta (8.8) | 8.7% | 💥 PoC | Airoha Bluetooth Audio SDKAI | 4/8/2025 | 8/9/2026 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Aplazada | Alta (8.8) | 9.2% | 💥 PoC | Airoha Bluetooth Audio SDKAI | 4/8/2025 | 17/6/2026 | In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Aplazada | Media (5.1) | 0.15% | — | Bluebird Barcode Scanner ApplicationAI | 17/7/2025 | 17/6/2026 | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite… | |
| Aplazada | Media (6.3) | 0.13% | — | Bluebird DevicesAI | 17/7/2025 | 17/6/2026 | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level permissions.… | |
| Aplazada | Alta (8.5) | 0.15% | — | Bluebird KioskAI | 17/7/2025 | 17/6/2026 | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects all versions before… | |
| Analizada | Baja (2.9) | 0.81% | — | Mao888 Bluebell-plus | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the file bluebell_backend/pkg/jwt/jwt.go of the component JWT Token Handler. The manipulation of the argument mySecret with the input bluebell-plus leads to use of… | |
| Modificada | Crítica (9.3) | 0.66% | — | 5vtechnologies Blue Angel Software Suite | 24/6/2025 | 17/6/2026 | A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain… | |
| Modificada | Alta (7.7) | 11% | 💥 Exploit | 5vtechnologies Blue Angel Software Suite | 24/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary… | |
| Aplazada | Media (6.5) | 0.23% | — | Blueglass Jobs FOR WordpressAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2.7.14. | |
| Aplazada | Alta (8.5) | 0.20% | — | Realtek Bluetooth HCI AdaptorAI | 2/6/2025 | 17/6/2026 | Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to… | |
| Analizada | Media (4.3) | 0.18% | — | Bluetrait Blue Trait Event Viewer | 15/5/2025 | 17/6/2026 | The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (5) | 0.34% | — | Bluewavelabs CheckmateAI | 15/5/2025 | 17/6/2026 | In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint. | |
| Aplazada | Alta (8.7) | 0.27% | — | Siemens Versicharge Blue EV ChargerAISiemens IEC EV ChargerAI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m incl. SIM… | |
| Aplazada | Media (5.7) | 0.14% | — | BlueframeAI | 12/5/2025 | 17/6/2026 | A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred. | |
| Aplazada | Alta (8.8) | 0.52% | — | Bluewavelabs CheckmateAI | 10/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter. | |
| Aplazada | Alta (8.1) | 0.50% | — | Bluewavelabs CheckmateAI | 4/5/2025 | 17/6/2026 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. | |
| Aplazada | Alta (7.1) | 0.29% | — | LEE Blue Cart66 CloudAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud cart66-cloud allows Reflected XSS.This issue affects Cart66 Cloud: from n/a through <= 2.3.7. | |
| Analizada | Media (4.3) | 0.41% | — | Bluecms Project Bluecms | 10/4/2025 | 17/6/2026 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. | |
| Aplazada | Alta (7.1) | 0.21% | — | Blueinstyle Advanced TAG ListsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blueinstyle Advanced Tag Lists advanced-tag-list allows Stored XSS.This issue affects Advanced Tag Lists: from n/a through <= 1.2. | |
| Analizada | Alta (7.5) | 0.43% | — | Canonical Linux-bluefield | 31/3/2025 | 17/6/2026 | Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package. | |
| Analizada | Media (5.3) | 0.45% | — | Bluestar Micro Mall | 30/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.50% | — | Bluestar Micro Mall | 30/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (7.1) | 0.31% | — | Jotis Blue CaptchaAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jotis Blue Captcha blue-captcha allows Reflected XSS.This issue affects Blue Captcha: from n/a through <= 1.7.4. |