Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
453 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.54% | — | Wisdmlabs Edwiser Bridge | 7/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.2. | |
| Analizada | Alta (7.5) | 0.65% | — | Chirpstack Gateway BridgeChirpstack Mqtt Forwarder | 21/3/2024 | 17/6/2026 | The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state. | |
| Analizada | Media (5.5) | 0.36% | — | Adobe Bridge | 18/3/2024 | 17/6/2026 | Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious… | |
| Analizada | Alta (7.8) | 4.1% | — | Adobe Bridge | 18/3/2024 | 17/6/2026 | Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 4.4% | — | Adobe Bridge | 18/3/2024 | 17/6/2026 | Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 7.8% | — | Adobe Bridge | 18/3/2024 | 17/6/2026 | Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (8.8) | 1.7% | — | Laurelbridge Dicom Connectivity FrameworkAI | 1/3/2024 | 17/6/2026 | Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file. | |
| Modificada | Crítica (9.1) | 0.68% | — | Precisionbridge Precision Bridge | 26/11/2023 | 17/6/2026 | Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address. | |
| Modificada | Media (5.5) | 0.37% | — | Adobe Bridge | 16/11/2023 | 17/6/2026 | Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction… | |
| Modificada | Media (5.5) | 0.40% | — | Adobe Bridge | 16/11/2023 | 17/6/2026 | Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim… | |
| Modificada | Media (5.5) | 0.37% | — | Adobe Bridge | 16/11/2023 | 17/6/2026 | Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction… | |
| Analizada | Media (6.1) | 0.69% | — | Debian LinuxSensiolabs SymfonySymfony Twig-bridge | 10/11/2023 | 29/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51,… | |
| Modificada | Media (5.5) | 0.40% | — | Adobe Bridge | 11/10/2023 | 17/6/2026 | Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a… | |
| Modificada | Media (5.5) | 0.43% | — | Adobe Bridge | 11/10/2023 | 17/6/2026 | Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim… | |
| Modificada | Alta (7.5) | 0.78% | — | Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+5 | 10/10/2023 | 17/6/2026 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a… | |
| Modificada | Media (6.1) | 0.38% | — | Qodeinteractive Bridge Core | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions. | |
| Modificada | Baja (3.7) | 0.60% | — | Matrix IRC Bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the… | |
| Modificada | Media (6.5) | 0.47% | — | Matrix-appservice-bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning API. The library does not check that the… | |
| Modificada | Crítica (9.8) | 0.86% | — | Matrix IRC Bridge | 4/8/2023 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are… | |
| Modificada | Alta (8.8) | 0.45% | — | Edwiser Bridge | 1/7/2023 | 17/6/2026 | The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(),… | |
| Modificada | Media (5.4) | 0.45% | — | Sitebridge Joruri GW | 10/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject an arbitrary script via Message Memo function of the affected product. | |
| Modificada | Alta (7.5) | 1.00% | — | Seiko-sol Skybridge Basic Mb-a130 FirmwareSeiko-sol Skybridge Mb-a200 FirmwareSeiko-sol Skyspider Mb-r210 Firmware | 10/5/2023 | 17/6/2026 | Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware… | |
| Modificada | Alta (7.5) | 0.83% | — | Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware | 10/5/2023 | 17/6/2026 | Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. | |
| Modificada | Media (6.5) | 0.51% | — | Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware | 10/5/2023 | 17/6/2026 | Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attacker may eavesdrop on or alter the administrator's communication to the product. | |
| Modificada | Media (6.5) | 0.55% | — | Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware | 10/5/2023 | 17/6/2026 | Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product. |