Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.5%—Tibco Spotfire Deployment KITTibco Spotfire ProfessionalTibco Spotfire WEB PlayerTibco Spotfire Desktop+521/7/201517/6/2026
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3,…
ModificadaMedia (6.4)1.5%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify settings via unspecified vectors, a different vulnerability than CVE-2015-2952 and CVE-2015-2953.
ModificadaMedia (5)1.4%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read files via unspecified vectors, a different vulnerability than CVE-2015-2952 and CVE-2015-2958.
ModificadaMedia (6.5)1.2%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and…
ModificadaMedia (4.3)1.2%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.3%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
SQL injection vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.6%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
ModificadaMedia (6.8)0.64%—Igreks Milkystep LightIgreks Milkystep ProfessionalIgreks Milkystep Professional OEM13/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (6.4)1.2%—Ashampoo Gmbh & CO. Ashampoo 3D CAD Professional 31/1/201516/6/2026
The SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx in Ashampoo 3D CAD Professional 3.x before 3.0.2 allows remote attackers to write to arbitrary files via a pathname in the first argument.
ModificadaMedia (5.4)0.27%—Th3professional TH3 Professional AL Mohtarif15/10/201417/6/2026
The TH3 professional Al Mohtarif (aka com.th3professional.almohtarif) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (3.5)0.95%—Drupal Professional Theme9/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.
ModificadaMedia (5.4)0.27%—Passion4profession Chest Workout9/9/201417/6/2026
The Chest Workout (aka net.p4p.chest) application 2.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Passion4profession 8 Minutes ABS Workout9/9/201417/6/2026
The 8 Minutes Abs Workout (aka net.p4p.absen) application 2.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)3.1%—Tibco WEB PlayerTibco Automation ServicesTibco Spotfire ServerTibco Spotfire Professional+310/4/201417/6/2026
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before…
ModificadaBaja (2.1)0.94%—Devsaran Professional Theme27/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.6%—Tibco Spotfire Analytics ServerTibco Spotfire ServerTibco WEB Player Automation ServicesTibco Spotfire Professional13/3/201216/6/2026
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a…
ModificadaAlta (7.5)1.0%💥 ExploitOnlinetechtools.com Oasys Professional5/11/201016/6/2026
SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.6)3.3%—RIM Blackberry Enterprise ServerRIM Blackberry Professional Software14/10/201016/6/2026
Multiple buffer overflows in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.7 and earlier and 5.0.0 through 5.0.2, and BlackBerry Professional Software 4.1.4 and earlier, allow user-assisted remote attackers to cause a denial of service…
ModificadaAlta (9.3)4.3%—RIM Blackberry Enterprise ServerRIM Blackberry Professional Software21/4/201016/6/2026
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory…
ModificadaAlta (9.3)3.1%—Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+2121/4/201016/6/2026
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF…
ModificadaAlta (7.2)0.93%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional25/2/201016/6/2026
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses…
ModificadaAlta (9.3)5.6%💥 ExploitKlinza Professional CMS7/12/200916/6/2026
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG parameter.
ModificadaAlta (9.3)4.8%—Assistanttools MP3 TAG Assistance Professional4/12/200916/6/2026
Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute arbitrary code via an MP3 file with a long string in the (1) ID3v1, (2) ID3v2, or (3) APEv2 metadata field.
ModificadaAlta (7.2)1.1%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional23/11/200916/6/2026
Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted arguments to IOCTL 0x80002024.
ModificadaAlta (7.2)0.38%—Avast Antivirus HomeAvast Antivirus Professional1/10/200916/6/2026
Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.