Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.1) | 0.19% | — | Silabs Bluetooth LOW Energy Software Development KIT | 12/7/2024 | 17/6/2026 | Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0. | |
| Aplazada | Media (6.5) | 0.50% | — | Blue Plugins Events Calendar FOR GoogleAI | 12/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Calendar for Google allows PHP Local File Inclusion.This issue affects Events Calendar for Google: from n/a through 2.1.0. | |
| Aplazada | Baja (3.7) | 0.45% | — | BigbluebuttonAI | 28/6/2024 | 17/6/2026 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal of privilege escalation, potentially… | |
| Aplazada | Media (4.6) | 0.31% | — | BigbluebuttonAI | 28/6/2024 | 17/6/2026 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be "role=moderator", allowing an attacker to join a… | |
| Analizada | Media (5.4) | 0.29% | — | Blueastral Page Builder\ | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.42. | |
| Modificada | Media (4.8) | 0.32% | — | Blueastral Page Builder\ | 21/6/2024 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Aplazada | Crítica (9.1) | 2.2% | 💥 PoC | Boelter Blue System ManagementAI | 12/6/2024 | 17/6/2026 | SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php. | |
| Aplazada | Media (5.5) | 0.18% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.4) | 0.22% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Alta (7.8) | 0.41% | — | Bluerisc Windowsscope Cyber ForensicsAI | 14/5/2024 | 17/6/2026 | An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates. | |
| Aplazada | Alta (7.3) | 0.36% | 💥 PoC | Nordic Semiconductor NRF Sniffer FOR Bluetooth LEAI | 14/5/2024 | 17/6/2026 | extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts. | |
| Analizada | Crítica (9.8) | 0.84% | — | Bluenettechnology Clinical Browsing System | 8/5/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.66% | — | Bluenettechnology Clinical Browsing System | 8/5/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.5) | 0.65% | — | Brevo Sendinblue FOR WoocommerceAI | 6/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17. | |
| Analizada | Alta (7.1) | 1.5% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious… | |
| Analizada | Media (5.7) | 1.1% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth… | |
| Analizada | Media (5.7) | 0.81% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Media (5.7) | 0.82% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Media (5.7) | 0.96% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the… | |
| Modificada | Alta (8) | 1.5% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious… | |
| Modificada | Alta (8) | 2.3% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious… | |
| Analizada | Alta (8) | 1.6% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a… | |
| Modificada | Alta (8) | 1.4% | — | Bluez | 3/5/2024 | 17/6/2026 | BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect… | |
| Analizada | Media (6.5) | 12% | 💥 Exploit | Bluenettechnology Clinical Browsing System | 27/4/2024 | 17/6/2026 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/deleteStudy.php. The manipulation of the argument documentUniqueId leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (6.1) | 0.41% | — | Bigbluebutton Greenlight | 25/4/2024 | 17/6/2026 | Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue. |