Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.1)0.26%—Blacklanternsecurity Bbot8/7/202619/8/2026
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location…
AnalizadaBaja (3.1)0.38%—Blacklanternsecurity Bbot8/7/202619/8/2026
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for…
AplazadaBaja (3.1)0.17%—Docker RegistryAIBlacklanternsecurity BbotAI17/6/202622/6/2026
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary…
AplazadaCrítica (9.6)0.71%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
AplazadaCrítica (9.6)0.48%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
AplazadaMedia (4.7)0.23%—GitlabAIBlacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
AplazadaMedia (4.7)0.23%—Blacklanternsecurity BbotAI9/10/202517/6/2026
BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.
ModificadaMedia (5.2)0.29%—Abbott ID NOW Firmware14/11/202317/6/2026
The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modified via physical access to an internal serial port. Direct physical access is required to exploit.
ModificadaAlta (8.8)0.63%—Abbott Freestyle Libre Firmware16/2/202017/6/2026
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced…
ModificadaMedia (6.5)0.24%—Abbott Accent FirmwareAbbott Anthem FirmwareAbbott Accent MRI FirmwareAbbott Accent ST Firmware25/4/201817/6/2026
Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers store the optional patient information without encryption. CVSS v3 base score: 3.1,…
ModificadaMedia (6.5)0.65%—Abbott Accent FirmwareAbbott Anthem FirmwareAbbott Accent MRI FirmwareAbbott Accent ST Firmware+325/4/201817/6/2026
Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string:…
ModificadaAlta (8.8)1.1%—Abbott Accent FirmwareAbbott Anthem FirmwareAbbott Accent MRI FirmwareAbbott Accent ST Firmware+325/4/201817/6/2026
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS…
ModificadaAlta (8.9)1.2%—Abbott Merlin@home Firmware13/2/201717/6/2026
An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical's web site,…