Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | NewsblurAI | 25/6/2026 | 14/7/2026 | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notification feeds by supplying arbitrary user_id values to the GET /social/interactions endpoint without ownership verification. Attackers can enumerate user_id values to access another user's… | |
| Aplazada | Media (6.3) | 0.35% | — | NewsblurAI | 25/6/2026 | 14/7/2026 | NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata… | |
| Modificada | Media (6.8) | 0.32% | — | Blurams Dome Flare Firmware | 14/1/2026 | 5/7/2026 | An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The… | |
| Modificada | Media (6.1) | 0.21% | — | Blurams Dome Flare Firmware | 14/1/2026 | 5/7/2026 | A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data… | |
| Modificada | Media (6.8) | 0.29% | — | Blurams A31c Firmware | 24/11/2025 | 5/7/2026 | An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card. | |
| Aplazada | Media (6.5) | 0.35% | — | Linnea Huxford Blur TextAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford Blur Text blur-text allows Stored XSS.This issue affects Blur Text: from n/a through <= 1.0.0. | |
| Modificada | Media (6.8) | 0.48% | — | Blurams Lumi Security Camera A31c Firmware | 2/2/2024 | 17/6/2026 | An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.2% | — | Blurams Lumi Security Camera A31c Firmware | 2/2/2024 | 17/6/2026 | An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.62% | — | Whisperfish Blurhash-rs | 19/9/2023 | 17/6/2026 | blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due to multiple panic-guarded out-of-bounds accesses on untrusted input. In a… | |
| Modificada | Media (4.7) | 0.37% | — | Videolan LibblurayRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 22/11/2019 | 17/6/2026 | libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files | |
| Modificada | Alta (7.5) | 2.1% | — | Abine Blur | 29/3/2019 | 17/6/2026 | Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would require the user to accept a second-factor request in a mobile app." approach, related to a "Multifactor… | |
| Modificada | Crítica (9.8) | 1.6% | — | Abine Blur | 11/3/2018 | 17/6/2026 | The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context menu is not secured. | |
| Modificada | Media (4.3) | 1.2% | — | Blursoft Blur6ex | 14/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title. | |
| Modificada | Alta (7.5) | 1.5% | — | Blursoft Blur6ex | 19/6/2006 | 16/6/2026 | SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard. NOTE: This is a similar vulnerability to CVE-2006-1763, but the affected code and versions are different. | |
| Modificada | Alta (7.5) | 2.0% | — | Blursoft Blur6ex | 13/4/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter. NOTE: this issue can be exploited to produce resultant XSS when the parameter has XSS manipulations, and path disclosure with other invalid values. | |
| Modificada | Media (5) | 1.2% | — | Blursoft Blur6ex | 13/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_permaPost action to the blog shard (engine/shards/blog.php), or a (3) g_viewContent action to the content shard (engine/shards/content.php). | |
| Modificada | Baja (2.6) | 1.2% | — | Blursoft Blur6ex | 13/4/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name. |