Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.61%—F-secure Internet Gatekeeper28/9/202117/6/2026
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username…
ModificadaMedia (5.9)0.77%—Samsung Internet9/9/202117/6/2026
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
ModificadaMedia (6.5)0.58%—Cypress Wireless Internet Connectivity FOR Embedded Devices7/9/202117/6/2026
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a…
ModificadaMedia (6.5)0.58%—Cypress Wireless Internet Connectivity FOR Embedded Devices7/9/202117/6/2026
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to exhaust device BT resources and eventually trigger a crash via…
ModificadaMedia (5.3)0.51%—Cypress Wireless Internet Connectivity FOR Embedded Devices7/9/202117/6/2026
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a…
ModificadaMedia (5.3)0.75%—Samsung Internet5/8/202117/6/2026
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
ModificadaMedia (4.3)0.55%—SAP WEB DispatcherSAP Internet Communication Manager14/7/202117/6/2026
SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73, WEBDISP 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, KERNEL 7.21, 7.22,…
ModificadaAlta (7.5)0.54%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security22/6/202117/6/2026
Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security…
ModificadaMedia (6.5)0.76%—Samsung Internet11/6/202117/6/2026
Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.
ModificadaAlta (7.8)0.23%—Samsung Internet11/6/202117/6/2026
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
ModificadaAlta (7.8)0.23%—Samsung Internet11/6/202117/6/2026
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an…
ModificadaMedia (5.9)0.86%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory…
ModificadaAlta (7.5)23%—Microsoft Internet Explorer11/5/202117/6/2026
Scripting Engine Memory Corruption Vulnerability
ModificadaMedia (4.3)0.78%—Oracle Internet Expenses22/4/202117/6/2026
Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Expenses. Successful…
ModificadaMedia (6.1)0.73%—Wfiltericf Wfilter Internet Content Filter15/4/202117/6/2026
Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.
ModificadaMedia (5.5)0.22%—Kaspersky Internet Security1/4/202117/6/2026
KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.
ModificadaBaja (2.9)0.27%—Samsung Internet25/3/202117/6/2026
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
ModificadaMedia (5.3)0.46%—Samsung Internet25/3/202117/6/2026
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
AnalizadaAlta (8.8)5.4%⚠ Explotación activaMicrosoft Internet Explorer11/3/202119/8/2026
Internet Explorer Remote Code Execution Vulnerability