Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 18% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 20/7/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Analizada | Alta (7.8) | 25% | ⚠ Explotación activa | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.5) | 13% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 14% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 6.7% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/7/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (7.5) | 1.4% | — | Theflashtoken Project Theflashtoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for TheFlashToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (6.5) | 1.6% | — | IBM Flashsystem 900 FirmwareIBM Flashsystem 840 Firmware | 29/5/2018 | 17/6/2026 | IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service. IBM X-Force ID: 141148. | |
| Modificada | Crítica (9.8) | 8.6% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 26% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.5) | 25% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 26% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Media (6.5) | 20% | 💥 Exploit | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (6.5) | 4.1% | — | Adobe Flash PlayerAdobe Flash Player Desktop Runtime | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Flash PlayerAdobe Flash Player Desktop Runtime | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 7.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Alta (8.8) | 7.4% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 19/5/2018 | 17/6/2026 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | |
| Modificada | Crítica (9.8) | 3.5% | — | Tinywebgallery Wordpress Flash Uploader | 25/4/2018 | 17/6/2026 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. | |
| Modificada | Media (5.3) | 1.0% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default. | |
| Modificada | Media (5.3) | 1.0% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory. | |
| Modificada | Crítica (9.8) | 1.1% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices have a default VNC password. | |
| Modificada | Crítica (9.8) | 2.8% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. | |
| Analizada | Alta (7.8) | 90% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 6/2/2018 | 17/6/2026 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and… | |
| Modificada | Crítica (9.8) | 8.3% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 6/2/2018 | 17/6/2026 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.4% | — | Fop2 Flash Operator Panel | 14/1/2018 | 17/6/2026 | The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 allows remote authenticated users to execute arbitrary commands via the command parameter. | |
| Modificada | Alta (7.5) | 5.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/1/2018 | 17/6/2026 | An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A… |