Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.6%—Blackberry QNX Software Development Platform12/8/202017/6/2026
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
ModificadaMedia (5.8)2.7%💥 ExploitPrometheus Blackbox Exporter9/8/202017/6/2026
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability
AnalizadaMedia (6.5)86%⚠ Explotación activa💥 ExploitSaltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+230/4/202017/6/2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
ModificadaMedia (5.4)0.62%💥 PoCBlackboard Learn25/2/202017/6/2026
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitApache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+1724/2/202025/8/2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.…
ModificadaMedia (6.5)2.1%—Blackberry Playbook Firmware10/2/202016/6/2026
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
ModificadaMedia (6.1)1.2%💥 PoCBlackboard Learn18/11/201917/6/2026
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
ModificadaBaja (3.3)0.28%—Blackview Bv7000 PRO Firmware14/11/201917/6/2026
The Blackview BV7000_Pro Android device with a build fingerprint of Blackview/BV7000_Pro/BV7000_Pro:7.0/NRD90M/1493011204:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a…
ModificadaBaja (3.3)0.28%—Blackview Bv9000pro-f Firmware14/11/201917/6/2026
The Blackview BV9000Pro-F Android device with a build fingerprint of Blackview/BV9000Pro-F/BV9000Pro-F:7.1.1/N4F26M/1514363110:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a…
ModificadaCrítica (9.8)2.9%—Blackbox Icompel FirmwareOnelan Net-top-box Firmware26/8/201917/6/2026
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
ModificadaAlta (7.8)0.22%—Blackberry QNX Software Development Platform12/7/201917/6/2026
An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attacker to potentially gain unauthorized access to a chosen process address space.
ModificadaCrítica (9.8)7.0%—Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+830/4/201917/6/2026
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitCrestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+830/4/201917/6/2026
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,…
ModificadaAlta (7.5)1.5%—Blackberry Unified Endpoint Management18/4/201917/6/2026
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
ModificadaMedia (5.9)2.3%💥 PoCBlackberry Athoc21/3/201917/6/2026
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing…
ModificadaMedia (6.5)0.41%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.
ModificadaMedia (4.8)0.51%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
ModificadaMedia (4.8)0.51%—Blackberry Unified Endpoint Manager20/12/201817/6/2026
A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.
ModificadaMedia (5.4)0.57%—Blackcat-cms Blackcat CMS10/12/201817/6/2026
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
ModificadaAlta (7.5)1.1%—Blackberry Unified Endpoint Manager12/10/201817/6/2026
An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user.
ModificadaMedia (4.7)0.48%—Blackberry Enterprise Mobility Server19/9/201817/6/2026
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
ModificadaAlta (7.5)0.89%—Ethereumblack Project Ethereumblack5/7/201817/6/2026
The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
ModificadaAlta (7.5)0.93%—Ethereumblack Project Ethereumblack3/7/201817/6/2026
The mintToken function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaMedia (4.8)1.0%💥 PoCBlackcat-cms Blackcat CMS14/6/201817/6/2026
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.
ModificadaMedia (5.5)0.44%—Carbonblack Carbon Black CB13/6/201817/6/2026
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will…
Orbitaley — Vulnerabilidades