Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)18%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+120/7/201817/6/2026
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
AnalizadaAlta (7.8)25%⚠ Explotación activaAdobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (6.5)13%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (6.5)14%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)6.7%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/7/201817/6/2026
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (7.5)1.4%—Theflashtoken Project Theflashtoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for TheFlashToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaMedia (6.5)1.6%—IBM Flashsystem 900 FirmwareIBM Flashsystem 840 Firmware29/5/201817/6/2026
IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148.
ModificadaCrítica (9.8)8.6%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)26%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (6.5)25%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)26%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaMedia (6.5)20%💥 ExploitAdobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (6.5)4.1%—Adobe Flash PlayerAdobe Flash Player Desktop Runtime19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (8.8)5.1%—Adobe Flash PlayerAdobe Flash Player Desktop Runtime19/5/201817/6/2026
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)7.6%—Adobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaAlta (8.8)7.4%—Adobe Flash Player Desktop RuntimeAdobe Flash Player19/5/201817/6/2026
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
ModificadaCrítica (9.8)3.5%—Tinywebgallery Wordpress Flash Uploader25/4/201817/6/2026
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
ModificadaMedia (5.3)1.0%—Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+420/2/201817/6/2026
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.
ModificadaMedia (5.3)1.0%—Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+420/2/201817/6/2026
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.
ModificadaCrítica (9.8)1.1%—Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+420/2/201817/6/2026
Datto ALTO and SIRIS devices have a default VNC password.
ModificadaCrítica (9.8)2.8%—Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+420/2/201817/6/2026
Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.
AnalizadaAlta (7.8)90%⚠ Explotación activa💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation6/2/201817/6/2026
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and…
ModificadaCrítica (9.8)8.3%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation6/2/201817/6/2026
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.
ModificadaAlta (8.8)2.4%—Fop2 Flash Operator Panel14/1/201817/6/2026
The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 allows remote authenticated users to execute arbitrary commands via the command parameter.
ModificadaAlta (7.5)5.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player9/1/201817/6/2026
An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A…