Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Sharp-nec-displays Un462a FirmwareSharp-nec-displays Un462va FirmwareSharp-nec-displays Un492s FirmwareSharp-nec-displays Un492vs Firmware+307/6/202117/6/2026
Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and…
ModificadaMedia (5.9)1.5%—Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java20/5/202117/6/2026
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic…
ModificadaCrítica (9.8)3.4%—Sharpred Deephas12/11/202017/6/2026
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
AnalizadaAlta (8.8)48%⚠ Explotación activaCefsharpGoogle ChromeMicrosoft EdgeMicrosoft Edge Chromium+43/11/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (7.5)1.2%—Sharp Aquos Sh-m02 FirmwareSharp Aquos Sh-rm02 FirmwareSharp Aquos Mini Sh-m03 FirmwareSharp Aquos L2 Firmware+623/4/202017/6/2026
SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build number 01.00.01 and earlier, AQUOS L2 (UQ mobile/J:COM) build number 01.00.05 and earlier, AQUOS sense lite SH-M05 build…
ModificadaAlta (7.3)0.36%—Jetbrains Resharper2/10/201917/6/2026
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
ModificadaCrítica (9.8)1.4%—Xayr Xenfcoresharp26/8/201917/6/2026
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
ModificadaMedia (4.2)0.18%—MI 5S Plus FirmwareSony Xperia Z4 FirmwareSamsung Galaxy S6 Edge FirmwareSamsung Galaxy S4 Firmware+46/6/201917/6/2026
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.
ModificadaCrítica (9.8)7.0%—Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+830/4/201917/6/2026
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,…
AnalizadaCrítica (9.8)99%⚠ Explotación activaCrestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+830/4/201917/6/2026
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,…
ModificadaAlta (8.8)15%—Microsoft Azure Internet OF Things EdgeMicrosoft Csharp Software Development KIT10/10/201817/6/2026
A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge.
ModificadaAlta (7.8)1.6%—Jetbrains DotpeekJetbrains Resharper Ultimate13/8/201817/6/2026
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
ModificadaMedia (5.5)9.9%—Sharpziplib Project Sharpziplib25/7/201817/6/2026
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaMedia (5.5)9.4%—Adamhathcock Sharpcompress25/7/201817/6/2026
SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaMedia (5.6)1.2%—Microsoft C Software Development KITMicrosoft Csharp Software Development KITMicrosoft Java Software Development KIT9/5/201817/6/2026
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.
ModificadaMedia (4.6)0.42%—Sharp Rx-v200 FirmwareSharp Rx-v100 FirmwareSharp Rx-clv1-p FirmwareSharp Rx-clv2-b Firmware+117/11/201717/6/2026
Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform…
ModificadaAlta (7.8)1.6%—Sharp Rw-51009/6/201717/6/2026
Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—Sharp Rw-5100 Driver Installer FOR Windows 7Sharp Rw-5100 Driver Installer FOR Windows 8.19/6/201717/6/2026
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.6%—Sharp Rw-40409/6/201717/6/2026
Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—Sharp Rw-40409/6/201717/6/2026
Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.3)1.1%—Sharp EVA Animator5/4/201617/6/2026
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
ModificadaMedia (4.3)0.76%—Sharp Aquos Hn-pp150 Firmware5/4/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
ModificadaCrítica (9.8)4.6%—Zhuhai Raysharp Firmware18/2/201617/6/2026
Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.
ModificadaMedia (4.6)0.38%—Disney Interactive Disney MobileFujitsu Arrows TAB LTE F-01dSharp Softbank 102shFujitsu Regza Phone T-01d+25/12/201417/6/2026
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary…
ModificadaMedia (5)1.9%—Sharp Aquos Hn-pp150 FirmwareSharp Aquos Hn-pp15012/7/201316/6/2026
The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data.