Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.81% | — | Redisbloom | 5/5/2026 | 25/7/2026 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded… | |
| Analizada | Media (6.1) | 0.35% | — | Bloomberg Memray | 18/3/2026 | 17/6/2026 | Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed… | |
| Analizada | Alta (7.5) | 0.27% | — | Lfprojects Valkey-bloom | 24/2/2026 | 17/6/2026 | Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to commit a68614b6e3845777d383b3a513cedcc08b3b7ccd, a specially crafted `RESTORE` command can cause Valkey to hit an assertion, causes the server to shutdown. Valkey modules… | |
| Modificada | Alta (7.5) | 0.58% | — | Bloomberg Comdb2 | 22/7/2025 | 17/6/2026 | A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send… | |
| Modificada | Alta (7.5) | 0.83% | — | Bloomberg Comdb2 | 22/7/2025 | 17/6/2026 | A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to a denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.88% | — | Bloomberg Comdb2 | 22/7/2025 | 17/6/2026 | A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to a denial of service. An attacker can send packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.55% | — | Bloomberg Comdb2 | 22/7/2025 | 17/6/2026 | A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this… | |
| Modificada | Alta (7.5) | 0.58% | — | Bloomberg Comdb2 | 22/7/2025 | 17/6/2026 | A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2 8.1. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this… | |
| Aplazada | Alta (8.8) | 15% | — | RedisbloomAI | 8/1/2025 | 17/6/2026 | RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows an attacker (a redis client which knows the password) to allocate memory in the heap lesser than the required memory due… | |
| Aplazada | Alta (7.1) | 0.35% | — | Bloompixel MAX Addons PRO FOR BricksAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1. | |
| Aplazada | Media (6.5) | 0.44% | — | Bloompixel MAX Addons PRO FOR BricksAI | 24/4/2024 | 17/6/2026 | Missing Authorization vulnerability in BloomPixel Max Addons Pro for Bricks.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1. | |
| Aplazada | Media (5.5) | 0.20% | — | RedisbloomAI | 9/4/2024 | 17/6/2026 | RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the `CF.RESERVE` command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10. | |
| Aplazada | Alta (7) | 0.42% | — | RedisbloomAI | 9/4/2024 | 17/6/2026 | RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and… | |
| Modificada | Alta (7.8) | 0.40% | — | Bloom Project Bloom | 12/1/2023 | 17/6/2026 | Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1. | |
| Modificada | Alta (7.8) | 0.35% | — | Quarkslab Binbloom | 14/12/2022 | 17/6/2026 | Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c. | |
| Modificada | Media (6.5) | 0.59% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended. | |
| Modificada | Media (5.4) | 0.60% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image… | |
| Modificada | Alta (7.2) | 3.6% | — | Bloomreach Experience Manager | 11/3/2021 | 17/6/2026 | An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation… | |
| Analizada | Alta (8.8) | 1.9% | — | Elegantthemes Bloom | 20/9/2019 | 17/6/2026 | The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. | |
| Modificada | Media (5.4) | 0.27% | — | Bloomyou Valentine | 19/10/2014 | 17/6/2026 | The BloomYou Valentine (aka com.bloomyouteam.bloomyou.valentine) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Parentlink Bloom Township 206 | 29/9/2014 | 17/6/2026 | The Bloom Township 206 (aka net.parentlink.bloom) application 4.0.500 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.6) | 2.3% | — | Studio Achtundachtzig Bloomooweb Activex Control | 3/11/2006 | 16/6/2026 | BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path… |