Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

453 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.54%—Wisdmlabs Edwiser Bridge7/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.2.
AnalizadaAlta (7.5)0.65%—Chirpstack Gateway BridgeChirpstack Mqtt Forwarder21/3/202417/6/2026
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.
AnalizadaMedia (5.5)0.36%—Adobe Bridge18/3/202417/6/2026
Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaAlta (7.8)4.1%—Adobe Bridge18/3/202417/6/2026
Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)4.4%—Adobe Bridge18/3/202417/6/2026
Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)7.8%—Adobe Bridge18/3/202417/6/2026
Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaAlta (8.8)1.7%—Laurelbridge Dicom Connectivity FrameworkAI1/3/202417/6/2026
Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.
ModificadaCrítica (9.1)0.68%—Precisionbridge Precision Bridge26/11/202317/6/2026
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on multiple systems, via vectors involving a Process Hacker memory dump, error message inspection, and modification of a MAC address.
ModificadaMedia (5.5)0.37%—Adobe Bridge16/11/202317/6/2026
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction…
ModificadaMedia (5.5)0.40%—Adobe Bridge16/11/202317/6/2026
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim…
ModificadaMedia (5.5)0.37%—Adobe Bridge16/11/202317/6/2026
Adobe Bridge versions 13.0.4 (and earlier) and 14.0.0 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction…
AnalizadaMedia (6.1)0.69%—Debian LinuxSensiolabs SymfonySymfony Twig-bridge10/11/202329/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51,…
ModificadaMedia (5.5)0.40%—Adobe Bridge11/10/202317/6/2026
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.43%—Adobe Bridge11/10/202317/6/2026
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim…
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaMedia (6.1)0.38%—Qodeinteractive Bridge Core27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions.
ModificadaBaja (3.7)0.60%—Matrix IRC Bridge4/8/202317/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the…
ModificadaMedia (6.5)0.47%—Matrix-appservice-bridge4/8/202317/6/2026
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning API. The library does not check that the…
ModificadaCrítica (9.8)0.86%—Matrix IRC Bridge4/8/202317/6/2026
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are…
ModificadaAlta (8.8)0.45%—Edwiser Bridge1/7/202317/6/2026
The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(),…
ModificadaMedia (5.4)0.45%—Sitebridge Joruri GW10/5/202317/6/2026
Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject an arbitrary script via Message Memo function of the affected product.
ModificadaAlta (7.5)1.00%—Seiko-sol Skybridge Basic Mb-a130 FirmwareSeiko-sol Skybridge Mb-a200 FirmwareSeiko-sol Skyspider Mb-r210 Firmware10/5/202317/6/2026
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware…
ModificadaAlta (7.5)0.83%—Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware10/5/202317/6/2026
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
ModificadaMedia (6.5)0.51%—Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware10/5/202317/6/2026
Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attacker may eavesdrop on or alter the administrator's communication to the product.
ModificadaMedia (6.5)0.55%—Seiko-sol Skybridge Mb-a110 FirmwareSeiko-sol Skybridge Mb-a100 Firmware10/5/202317/6/2026
Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product.
Orbitaley — Vulnerabilidades