Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.1) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure. | |
| Modificada | Alta (7.5) | 0.31% | — | Nvidia Geforce GT 605Nvidia Geforce GT 610Nvidia Geforce GT 620Nvidia Geforce GT 625+59 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact… | |
| Modificada | Media (4.4) | 0.20% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+103 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure. | |
| Modificada | Media (4.4) | 0.21% | — | Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+131 | 20/11/2021 | 17/6/2026 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure. | |
| Modificada | Alta (7.8) | 0.30% | — | Blackberry Protect | 10/11/2021 | 17/6/2026 | An elevation of privilege vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the system. | |
| Modificada | Media (5.5) | 0.26% | — | Blackberry Protect | 10/11/2021 | 17/6/2026 | A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the system and gaining the ability to delete data from the local… | |
| Modificada | Alta (7.8) | 0.30% | — | Blackberry Protect | 10/11/2021 | 17/6/2026 | A denial of service vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and earlier could allow an attacker to potentially execute code in the context of a BlackBerry Cylance service that has admin rights on the system. | |
| Modificada | Crítica (9.8) | 1.8% | — | Blackberry QNX Software Development PlatformBlackberry QNX OS FOR MedicalBlackberry QNX OS FOR Safety | 17/8/2021 | 17/6/2026 | An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially… | |
| Modificada | Media (5.4) | 0.62% | 💥 PoC | Blackboard Learn | 20/7/2021 | 17/6/2026 | Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form. | |
| Modificada | Media (5.4) | 0.56% | — | Blackboard Learn | 20/7/2021 | 17/6/2026 | Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor. | |
| Modificada | Media (4.8) | 0.54% | — | Blackcat-cms Blackcat CMS | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the 'Admin-Tools' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the 'Output Filters' and 'Droplets' modules. | |
| Modificada | Media (5.4) | 0.51% | — | Blackcat-cms Blackcat CMS | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the 'Add Page' feature of BlackCat CMS 1.3.6 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter. | |
| Modificada | Crítica (9.8) | 11% | — | Vmware Carbon Black APP Control | 23/6/2021 | 17/6/2026 | VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate. | |
| Modificada | Media (5.3) | 0.79% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially gain access to a victim's web history. | |
| Modificada | Alta (7.3) | 0.96% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially cause the spreadsheet application to run commands on the victim’s local machine with the authority of the user. | |
| Modificada | Media (5.5) | 0.22% | — | Blackberry Unified Endpoint Management | 13/5/2021 | 17/6/2026 | A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and earlier and 12.12.1a QF6 and earlier could allow an attacker to potentially to prevent any new user connections. | |
| Modificada | Alta (8.8) | 0.96% | — | Blackberry Workspaces Server | 13/5/2021 | 17/6/2026 | An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account. | |
| Modificada | Crítica (9.1) | 1.4% | — | Vmware Carbon Black Cloud Workload | 1/4/2021 | 17/6/2026 | VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue… | |
| Modificada | Media (6.1) | 0.69% | — | Blackboard Collaborate Ultra | 2/3/2021 | 17/6/2026 | Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research | |
| Modificada | Media (4.8) | 0.96% | — | Blackcat-cms Blackcat CMS | 16/2/2021 | 17/6/2026 | The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php. | |
| Modificada | Baja (3.6) | 0.21% | — | Vmware Carbon Black Cloud | 16/12/2020 | 17/6/2026 | The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation. | |
| Modificada | Crítica (9.8) | 2.1% | — | Blackfire Docker Image | 15/12/2020 | 17/6/2026 | The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Media (5.5) | 0.27% | — | Blackberry Unified Endpoint Manager | 14/10/2020 | 17/6/2026 | An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service. | |
| Modificada | Alta (8.8) | 6.3% | 💥 Exploit | Blackcat-cms Blackcat CMS | 15/9/2020 | 17/6/2026 | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. |