Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.6% | — | Blackberry QNX Software Development Platform | 12/8/2020 | 17/6/2026 | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server. | |
| Modificada | Media (5.8) | 2.7% | 💥 Exploit | Prometheus Blackbox Exporter | 9/8/2020 | 17/6/2026 | Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Modificada | Media (5.4) | 0.62% | 💥 PoC | Blackboard Learn | 25/2/2020 | 17/6/2026 | Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (6.5) | 2.1% | — | Blackberry Playbook Firmware | 10/2/2020 | 16/6/2026 | BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Blackboard Learn | 18/11/2019 | 17/6/2026 | The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page. | |
| Modificada | Baja (3.3) | 0.28% | — | Blackview Bv7000 PRO Firmware | 14/11/2019 | 17/6/2026 | The Blackview BV7000_Pro Android device with a build fingerprint of Blackview/BV7000_Pro/BV7000_Pro:7.0/NRD90M/1493011204:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a… | |
| Modificada | Baja (3.3) | 0.28% | — | Blackview Bv9000pro-f Firmware | 14/11/2019 | 17/6/2026 | The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a… | |
| Modificada | Crítica (9.8) | 2.9% | — | Blackbox Icompel FirmwareOnelan Net-top-box Firmware | 26/8/2019 | 17/6/2026 | Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. | |
| Modificada | Alta (7.8) | 0.22% | — | Blackberry QNX Software Development Platform | 12/7/2019 | 17/6/2026 | An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attacker to potentially gain unauthorized access to a chosen process address space. | |
| Modificada | Crítica (9.8) | 7.0% | — | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Modificada | Alta (7.5) | 1.5% | — | Blackberry Unified Endpoint Management | 18/4/2019 | 17/6/2026 | An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account. | |
| Modificada | Media (5.9) | 2.3% | 💥 PoC | Blackberry Athoc | 21/3/2019 | 17/6/2026 | An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing… | |
| Modificada | Media (6.5) | 0.41% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator. | |
| Modificada | Media (4.8) | 0.51% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator. | |
| Modificada | Media (4.8) | 0.51% | — | Blackberry Unified Endpoint Manager | 20/12/2018 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator. | |
| Modificada | Media (5.4) | 0.57% | — | Blackcat-cms Blackcat CMS | 10/12/2018 | 17/6/2026 | Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Blackberry Unified Endpoint Manager | 12/10/2018 | 17/6/2026 | An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user. | |
| Modificada | Media (4.7) | 0.48% | — | Blackberry Enterprise Mobility Server | 19/9/2018 | 17/6/2026 | A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account. | |
| Modificada | Alta (7.5) | 0.89% | — | Ethereumblack Project Ethereumblack | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 0.93% | — | Ethereumblack Project Ethereumblack | 3/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (4.8) | 1.0% | 💥 PoC | Blackcat-cms Blackcat CMS | 14/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel. | |
| Modificada | Media (5.5) | 0.44% | — | Carbonblack Carbon Black CB | 13/6/2018 | 17/6/2026 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will… |