Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.38% | — | Berkeley BoomAIBerkeley BoomtileAI | 19/8/2026 | 9/9/2026 | An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark… | |
| Aplazada | Alta (7.8) | 0.15% | — | Berkeley BoomAI | 18/8/2026 | 9/9/2026 | Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the… | |
| Aplazada | Media (5.3) | 0.43% | — | Nationaledtech BoomerangAI | 15/7/2026 | 15/7/2026 | ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029 | |
| Aplazada | Alta (7.1) | 0.36% | — | Nationaledtech BoomerangAI | 15/7/2026 | 15/7/2026 | ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from the webroot. This issue has been fixed… | |
| Analizada | Crítica (9.8) | 0.23% | — | Tecno Boomplay | 6/1/2026 | 30/9/2026 | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63. | |
| Aplazada | Media (4.3) | 0.27% | — | Boomdevs Wordpress Coming SoonAI | 31/12/2025 | 28/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon coming-soon-by-boomdevs allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.1) | 0.25% | — | Nuz007 SmsboomAI | 25/9/2025 | 17/6/2026 | A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is an unknown function of the file dy.php. Performing manipulation of the argument hm results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling… | |
| Aplazada | Media (5.1) | 0.25% | — | Nuz007 SmsboomAI | 25/9/2025 | 17/6/2026 | A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is an unknown function of the file d.php. Such manipulation of the argument hm leads to cross site scripting. The attack may be launched remotely. This product operates on a rolling release basis,… | |
| Aplazada | Baja (2.1) | 0.35% | — | Uxblondon BoomcmsAI | 3/9/2025 | 17/6/2026 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat… | |
| Analizada | Media (4.3) | 0.27% | — | Boom-core Boomv | 19/8/2025 | 17/6/2026 | A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd). This occurs despite the presence of proper… | |
| Analizada | Baja (1.1) | 0.16% | — | Boom-core Risvc-boom | 9/8/2025 | 17/6/2026 | A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component L1 Data Cache Handler. The manipulation leads to observable timing discrepancy. Local access is required to approach this attack. The complexity… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Afmobi BoomplayerAI | 16/6/2025 | 17/6/2026 | Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation. | |
| Aplazada | Alta (8.1) | 0.78% | — | Spyropress LA BoomAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SpyroPress La Boom allows PHP Local File Inclusion. This issue affects La Boom: from n/a through 2.7. | |
| Aplazada | Media (6.4) | 0.31% | — | BIG Boom DirectoryAI | 3/4/2025 | 17/6/2026 | The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.36% | — | Boombox Theme ExtensionsAI | 19/3/2025 | 17/6/2026 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the 'boombox_ajax_reset_password' function. This makes… | |
| Aplazada | Alta (8.8) | 0.60% | — | Boombox Theme ExtensionsAI | 3/2/2025 | 17/6/2026 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary… | |
| Modificada | Media (4.3) | 0.33% | — | Ibsofts Boom Fest | 25/1/2025 | 17/6/2026 | The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bf_admin_action' function in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings… | |
| Aplazada | Media (6.5) | 0.38% | — | Movement Ventures Boombox ShortcodeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Movement Ventures Boombox Shortcode boombox-shortcode allows DOM-Based XSS.This issue affects Boombox Shortcode: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Afmobi BoomplayerAI | 14/9/2024 | 17/6/2026 | Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks. | |
| Modificada | Crítica (9.1) | 1.1% | — | Nationaledtech Boomerang | 3/11/2023 | 17/6/2026 | An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing. | |
| Modificada | Media (4.6) | 0.54% | — | Nationaledtech Boomerang | 3/11/2023 | 17/6/2026 | An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate… | |
| Modificada | Media (5.4) | 0.58% | — | Uxblondon Boom CMS | 20/7/2023 | 17/6/2026 | A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.5) | 0.29% | — | Boom-core Riscvc-boomOpenhwgroup Cva6 | 18/7/2022 | 17/6/2026 | CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation. | |
| Modificada | Alta (8.1) | 2.0% | — | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (7.5) | 2.1% | — | B1 Eosio Batdappboomx | 13/5/2022 | 17/6/2026 | EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter. |