Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.48% | — | Adobe Bridge | 10/12/2024 | 17/6/2026 | Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.4) | 0.33% | — | Jalbum BridgeAI | 3/12/2024 | 17/6/2026 | The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.8) | 0.21% | — | Obs-scm-bridgeAI | 28/11/2024 | 17/6/2026 | Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service. | |
| Analizada | Media (5.5) | 0.24% | — | Adobe Bridge | 12/11/2024 | 17/6/2026 | Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user… | |
| Analizada | Media (5.5) | 0.27% | — | Adobe Bridge | 12/11/2024 | 17/6/2026 | Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Modificada | Media (5.4) | 0.28% | — | Edwiser Bridge | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge allows Stored XSS.This issue affects Edwiser Bridge: from n/a through <= 3.0.7. | |
| Modificada | Alta (8.6) | 0.23% | — | Edwiser Bridge | 17/10/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser Bridge: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.4) | 0.32% | — | Qodeinteractive Bridge CoreAI | 12/10/2024 | 17/6/2026 | The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level… | |
| Aplazada | Media (6.4) | 0.29% | — | Qodeinteractive Bridge CoreAI | 8/10/2024 | 17/6/2026 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Analizada | Alta (7.8) | 0.36% | — | Adobe Bridge | 14/8/2024 | 17/6/2026 | Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.40% | — | Adobe Bridge | 14/8/2024 | 17/6/2026 | Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Alta (7.8) | 0.36% | — | Adobe Bridge | 14/8/2024 | 17/6/2026 | Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Bridge | 9/7/2024 | 17/6/2026 | Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Alta (7.8) | 0.37% | — | Adobe Bridge | 9/7/2024 | 17/6/2026 | Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (7.5) | 0.44% | — | Lenovo Service BridgeAI | 13/6/2024 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a specially crafted link is visited. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Skybridge Mb-a100AISkybridge Mb-a110AISkybridge Mb-a130AI | 31/5/2024 | 17/6/2026 | Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the… | |
| Aplazada | Alta (7.2) | 0.43% | — | Opentext Operations Bridge ReporterAI | 17/5/2024 | 17/6/2026 | A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application. | |
| Aplazada | Alta (7.1) | 0.30% | — | Nuki BridgeAINuki Home Solutions BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects… | |
| Aplazada | Alta (8.8) | 0.29% | — | Nuki Smart Lock 3.0AINuki Bridge V1AINuki Bridge V2AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2. | |
| Aplazada | Alta (7.5) | 1.3% | — | Nuki BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. | |
| Aplazada | Media (6.4) | 0.43% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AINuki BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects… | |
| Aplazada | Crítica (9.8) | 1.6% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AINuki Bridge V1AINuki Bridge V2AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart… | |
| Aplazada | Media (6.3) | 1.3% | — | Nuki BridgeAINuki Home SolutionsAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. | |
| Aplazada | Crítica (9.8) | 0.90% | — | Edwiser BridgeAI | 7/5/2024 | 17/6/2026 | The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated… | |
| Analizada | Media (5.5) | 0.29% | — | Adobe Bridge | 11/4/2024 | 17/6/2026 | Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… |