Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.36% | — | Bigbluebutton Greenlight | 25/4/2024 | 17/6/2026 | Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue. | |
| Modificada | Media (6.1) | 0.39% | — | Blueglass Jobs FOR Wordpress | 18/4/2024 | 17/6/2026 | The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘job-search’ parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (4.9) | 0.89% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp BluexpNetapp Oncommand Insight+2 | 16/4/2024 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.1) | 0.40% | — | Blueglass Jobs FOR Wordpress | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for WordPress: from n/a through 2.7.5. | |
| Aplazada | Media (4.3) | 0.25% | — | Bluekitchen-gmbh BtstackAI | 1/4/2024 | 17/6/2026 | Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function. | |
| Modificada | Media (5.4) | 0.46% | — | Blueglass Jobs FOR Wordpress | 18/3/2024 | 17/6/2026 | The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.40% | — | Bluecoral Chat Bubble | 13/3/2024 | 17/6/2026 | The Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (7.5) | 65% | — | Squid-cache SquidFedoraproject FedoraNetapp Bluexp | 6/3/2024 | 17/6/2026 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP… | |
| Analizada | Alta (8) | 0.45% | — | Ciena Blue Planet Inventory | 6/3/2024 | 17/6/2026 | In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue… | |
| Modificada | Media (6.1) | 0.37% | — | Jbahlquist Blue Triad Ezanalytics | 5/3/2024 | 17/6/2026 | The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (8.8) | 0.21% | — | Bluecoral Advanced Flamingo | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0. | |
| Modificada | Alta (8.1) | 0.55% | — | Tencent Blueking Configuration Management Database | 26/2/2024 | 9/7/2026 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.4% | — | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp Bluexp | 26/2/2024 | 17/6/2026 | Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new… | |
| Analizada | Alta (7.5) | 88% | — | Squid-cache SquidNetapp Bluexp | 14/2/2024 | 17/6/2026 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending… | |
| Modificada | Media (5.4) | 0.31% | — | Blueastral Page Builder\ | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23. | |
| Modificada | Alta (7.5) | 1.1% | — | Mafiatic Blue Server | 25/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the component Connection Handler. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.2) | 0.75% | — | Nvidia Bluefield BMC | 24/1/2024 | 17/6/2026 | NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS. | |
| Modificada | Alta (7.2) | 0.50% | — | Blueastral Page Builder\ | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25. | |
| Modificada | Alta (8.8) | 0.26% | — | Bluecoral Chat Bubble | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blue Coral Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back.This issue affects Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back: from n/a through 2.3. | |
| Modificada | Media (4.3) | 0.13% | — | Midnightblue Tetra\ | 5/12/2023 | 17/6/2026 | The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 allows for efficient recovery of this 64-bit value, allowing an adversary to encrypt or decrypt arbitrary identities given only three known… | |
| Modificada | Media (6.8) | 1.3% | — | Bluetooth Core SpecificationMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+6 | 28/11/2023 | 17/6/2026 | Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS. | |
| Modificada | Media (5.4) | 0.42% | — | Bigbluebutton | 30/10/2023 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at `httpclient.execute` since the software no longer… | |
| Modificada | Media (5.4) | 0.42% | — | Bigbluebutton | 30/10/2023 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in… | |
| Modificada | Media (5.3) | 0.46% | — | Bigbluebutton | 30/10/2023 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain extensions (txt, swf, svg, png). In… | |
| Modificada | Alta (8.8) | 0.54% | — | Bigbluebutton | 30/10/2023 | 17/6/2026 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton… |