Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.42% | — | AXS Flash Seats | 16/12/2017 | 17/6/2026 | Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks. | |
| Modificada | Media (6.5) | 3.6% | — | Adobe Flash PlayerAdobe Flash Player Desktop RuntimeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 13/12/2017 | 17/6/2026 | A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data. | |
| Modificada | Crítica (9.8) | 6.2% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid… | |
| Modificada | Crítica (9.8) | 6.2% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal… | |
| Modificada | Crítica (9.8) | 6.1% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to… | |
| Modificada | Crítica (9.8) | 6.1% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption,… | |
| Modificada | Crítica (9.8) | 6.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationAdobe Flash Player | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque… | |
| Modificada | Crítica (9.8) | 34% | 💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 1/12/2017 | 17/6/2026 | Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier. | |
| Modificada | Crítica (9.8) | 34% | 💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 1/12/2017 | 17/6/2026 | Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier. | |
| Modificada | Crítica (9.8) | 3.5% | — | IBM Storwize V7000 FirmwareIBM Storwize V5000 FirmwareIBM Flashsystem V9000 FirmwareIBM SAN Volume Controller Firmware | 13/11/2017 | 17/6/2026 | A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-Force ID: 134531. | |
| Analizada | Alta (8.8) | 12% | ⚠ Explotación activa | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 22/10/2017 | 17/6/2026 | Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 22% | 💥 Exploit | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux WorkstationAdobe Flash Player Desktop Runtime+1 | 11/8/2017 | 17/6/2026 | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.4) | 4.5% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1 | 11/8/2017 | 17/6/2026 | Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect. | |
| Modificada | Alta (7.5) | 0.64% | — | Socusoft Flash Slideshow Maker | 5/8/2017 | 17/6/2026 | SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues. | |
| Modificada | Media (6.5) | 3.7% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 17/7/2017 | 17/6/2026 | Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure. | |
| Modificada | Alta (8.8) | 8.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 17/7/2017 | 17/6/2026 | Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 3 raster data model. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (6.5) | 4.2% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 17/7/2017 | 17/6/2026 | Adobe Flash Player versions 26.0.0.131 and earlier have a security bypass vulnerability related to the Flash API used by Internet Explorer. Successful exploitation could lead to information disclosure. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Flash PlayerAdobe Flash Player Extended Support ReleaseAdobe Flash Player FOR LinuxAdobe AIR+2 | 27/6/2017 | 17/6/2026 | Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Support Release before 18.0.0.324, Adobe Flash Player for Google Chrome before 20.0.0.267, Adobe Flash Player for Microsoft Edge and Internet Explorer 11 before 20.0.0.267, Adobe Flash Player for Internet… | |
| Modificada | Crítica (9.8) | 8.7% | — | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 14% | — | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 12% | — | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 14% | — | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 7.0% | — | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 31% | 💥 Exploit | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Adobe Flash Player | 20/6/2017 | 17/6/2026 | Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution. |