Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

190 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
ModificadaMedia (6.5)0.84%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
ModificadaMedia (6.5)1.4%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
ModificadaAlta (8.8)1.3%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
ModificadaMedia (6.5)0.57%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
ModificadaMedia (5.4)0.52%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
ModificadaMedia (6.5)0.59%—Bloomreach Experience Manager11/3/202117/6/2026
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.
ModificadaMedia (5.4)0.60%—Bloomreach Experience Manager11/3/202117/6/2026
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image…
ModificadaAlta (7.2)3.6%—Bloomreach Experience Manager11/3/202117/6/2026
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation…
ModificadaCrítica (9.6)2.7%—Bloodhound Project Bloodhound19/2/202117/6/2026
components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.
ModificadaMedia (4.9)1.3%—Bloofoxcms25/12/202017/6/2026
bloofoxCMS 0.5.2.1 allows admins to upload arbitrary .php files (with "Content-Type: application/octet-stream") to ../media/images/ via the admin/index.php?mode=tools&page=upload URI, aka directory traversal.
ModificadaCrítica (9.8)2.7%—Bloodx Project Bloodx2/12/202017/6/2026
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
AnalizadaAlta (8.8)1.9%—Elegantthemes Bloom20/9/201917/6/2026
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
ModificadaAlta (8.8)2.0%—Bloodhound Project Bloodhound27/8/201917/6/2026
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing…
ModificadaMedia (6.5)1.4%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely…
ModificadaAlta (7.1)1.6%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and…
ModificadaMedia (5.9)2.0%—Blipcare Wi-fi Blood Pressure Monitor Firmware2/7/201917/6/2026
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi…
ModificadaMedia (4.3)0.74%—Bloop Airmail21/8/201817/6/2026
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL handler only if the currentEvent is…
ModificadaMedia (5.3)0.88%—Bloop Airmail 321/8/201817/6/2026
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of HTMLFrameOwnerElements are not forbidden by the policy.…
ModificadaMedia (5.3)0.88%—Bloop Airmail 321/8/201817/6/2026
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment parameters. If the value of an attachment…
ModificadaMedia (5.9)4.1%—9folders NineApple MailBloop AirmailEmclient+1316/5/201817/6/2026
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
ModificadaMedia (5.9)5.5%—Apple MailBloop AirmailEmclientFlipdogsolutions Maildroid+716/5/201817/6/2026
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a…
ModificadaMedia (5.4)0.27%—Bloodjournal Blood20/10/201417/6/2026
The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Bloomyou Valentine19/10/201417/6/2026
The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Parentlink Bloom Township 20629/9/201417/6/2026
The Bloom Township 206 (aka net.parentlink.bloom) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.