Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.61% | — | F-secure Internet Gatekeeper | 28/9/2021 | 17/6/2026 | A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username… | |
| Modificada | Media (5.9) | 0.77% | — | Samsung Internet | 9/9/2021 | 17/6/2026 | Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token. | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in radio range to trigger a denial of service (firmware crash) via a… | |
| Modificada | Media (6.5) | 0.58% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to exhaust device BT resources and eventually trigger a crash via… | |
| Modificada | Media (5.3) | 0.51% | — | Cypress Wireless Internet Connectivity FOR Embedded Devices | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP setup procedure, allowing attackers in radio range to trigger a… | |
| Modificada | Media (5.3) | 0.75% | — | Samsung Internet | 5/8/2021 | 17/6/2026 | Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet. | |
| Modificada | Media (4.3) | 0.55% | — | SAP WEB DispatcherSAP Internet Communication Manager | 14/7/2021 | 17/6/2026 | SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.53, 7.73, WEBDISP 7.53, 7.73, 7.77, 7.81, 7.82, 7.83, KERNEL 7.21, 7.22,… | |
| Modificada | Alta (7.5) | 0.54% | — | Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 22/6/2021 | 17/6/2026 | Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to potentially bypass HTTP Strict Transport Security (HSTS) checks. This issue affects: Bitdefender Total Security versions prior to 25.0.7.29. Bitdefender Internet Security… | |
| Modificada | Media (6.5) | 0.76% | — | Samsung Internet | 11/6/2021 | 17/6/2026 | Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link. | |
| Modificada | Alta (7.8) | 0.23% | — | Samsung Internet | 11/6/2021 | 17/6/2026 | Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition. | |
| Modificada | Alta (7.8) | 0.23% | — | Samsung Internet | 11/6/2021 | 17/6/2026 | Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action. | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal… | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal… | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal… | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an… | |
| Modificada | Media (5.9) | 0.86% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal… | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an… | |
| Modificada | Media (5.9) | 1.2% | — | SAP Netweaver AS Internet Graphics Server | 9/6/2021 | 17/6/2026 | SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory… | |
| Modificada | Alta (7.5) | 23% | — | Microsoft Internet Explorer | 11/5/2021 | 17/6/2026 | Scripting Engine Memory Corruption Vulnerability | |
| Modificada | Media (4.3) | 0.78% | — | Oracle Internet Expenses | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Expenses. Successful… | |
| Modificada | Media (6.1) | 0.73% | — | Wfiltericf Wfilter Internet Content Filter | 15/4/2021 | 17/6/2026 | Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function. | |
| Modificada | Media (5.5) | 0.22% | — | Kaspersky Internet Security | 1/4/2021 | 17/6/2026 | KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection. | |
| Modificada | Baja (2.9) | 0.27% | — | Samsung Internet | 25/3/2021 | 17/6/2026 | Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication. | |
| Modificada | Media (5.3) | 0.46% | — | Samsung Internet | 25/3/2021 | 17/6/2026 | Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. | |
| Analizada | Alta (8.8) | 5.4% | ⚠ Explotación activa | Microsoft Internet Explorer | 11/3/2021 | 19/8/2026 | Internet Explorer Remote Code Execution Vulnerability |