Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.20% | — | Devinim Software Library SoftwareAI | 30/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS. This issue affects Library Software: before 24.11.02. | |
| Aplazada | Alta (8.1) | 0.54% | — | Cognition DevinAIMicrosoft VscodeAI | 16/12/2024 | 17/6/2026 | Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin… | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Alta (7.5) | 0.63% | — | Deviniti Issue Sync | 31/5/2023 | 9/7/2026 | An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser. | |
| Modificada | Media (6.8) | 1.1% | — | Devincentiis Gazie | 21/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password. | |
| Modificada | Alta (7.5) | 1.0% | — | Webdevindo-cms | 26/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL commands via the hal parameter. |