Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
190 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). | |
| Modificada | Media (6.5) | 0.84% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | |
| Modificada | Media (6.5) | 1.4% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header. | |
| Modificada | Media (6.5) | 0.57% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely). | |
| Modificada | Media (5.4) | 0.52% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter. | |
| Modificada | Media (6.5) | 0.59% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended. | |
| Modificada | Media (5.4) | 0.60% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image… | |
| Modificada | Alta (7.2) | 3.6% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation… | |
| Modificada | Crítica (9.6) | 2.7% | — | Bloodhound Project Bloodhound | 19/2/2021 | 17/6/2026 | components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter. | |
| Modificada | Media (4.9) | 1.3% | — | Bloofoxcms | 25/12/2020 | 17/6/2026 | bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal. | |
| Modificada | Crítica (9.8) | 2.7% | — | Bloodx Project Bloodx | 2/12/2020 | 17/6/2026 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. | |
| Analizada | Alta (8.8) | 1.9% | — | Elegantthemes Bloom | 20/9/2019 | 17/6/2026 | The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. | |
| Modificada | Alta (8.8) | 2.0% | — | Bloodhound Project Bloodhound | 27/8/2019 | 17/6/2026 | components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing… | |
| Modificada | Media (6.5) | 1.4% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely… | |
| Modificada | Alta (7.1) | 1.6% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and… | |
| Modificada | Media (5.9) | 2.0% | — | Blipcare Wi-fi Blood Pressure Monitor Firmware | 2/7/2019 | 17/6/2026 | It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi… | |
| Modificada | Media (4.3) | 0.74% | — | Bloop Airmail | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL handler only if the currentEvent is… | |
| Modificada | Media (5.3) | 0.88% | — | Bloop Airmail 3 | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of HTMLFrameOwnerElements are not forbidden by the policy.… | |
| Modificada | Media (5.3) | 0.88% | — | Bloop Airmail 3 | 21/8/2018 | 17/6/2026 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment parameters. If the value of an attachment… | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Media (5.9) | 5.5% | — | Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+7 | 16/5/2018 | 17/6/2026 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a… | |
| Modificada | Media (5.4) | 0.27% | — | Bloodjournal Blood | 20/10/2014 | 17/6/2026 | The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Bloomyou Valentine | 19/10/2014 | 17/6/2026 | The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Parentlink Bloom Township 206 | 29/9/2014 | 17/6/2026 | The Bloom Township 206 (aka net.parentlink.bloom) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |