Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | EvergreenAI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed… | |
| Aplazada | Alta (7.1) | 0.12% | — | Titopandub Evergreen Post TweeterAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS.This issue affects Evergreen Post Tweeter: from n/a through <= 1.8.9. | |
| Aplazada | Media (4.3) | 0.25% | — | Evergreencontentposter Evergreen Content PosterAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Evergreencontentposter Evergreen Content PosterAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Cross Site Request Forgery.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5. | |
| Analizada | Media (5.3) | 0.45% | — | Evergreencontentposter Evergreen Content Poster | 18/1/2025 | 17/6/2026 | The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_network_post() function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.31% | — | Evergreencontentposter Evergreen Content Poster | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2. | |
| Modificada | Media (6.1) | 0.40% | — | Evergreencontentposter Evergreen Content Poster | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1. | |
| Modificada | Media (4.8) | 0.39% | — | Evergreencontentposter Evergreen Content Poster | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media allows Stored XSS.This issue affects Evergreen Content Poster – Auto Post and Schedule Your Best Content to… | |
| Modificada | Alta (7.5) | 3.1% | — | Evergreen-ils Evergreen | 1/2/2018 | 17/6/2026 | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided. | |
| Modificada | Media (6.5) | 2.2% | — | Evergreen-ils Evergreen | 1/2/2018 | 17/6/2026 | Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL. | |
| Modificada | Media (6.5) | 2.2% | — | Evergreen-ils Evergreen | 1/2/2018 | 17/6/2026 | The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml. | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server From Rhui+5 | 11/5/2016 | 10/9/2026 | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016. | |
| Analizada | Alta (8.8) | 68% | ⚠ Explotación activa | Adobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash PlayerAdobe AIR+13 | 28/12/2015 | 17/6/2026 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified… | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa | Adobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+6 | 15/10/2015 | 17/6/2026 | Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015. | |
| Modificada | Alta (10) | 50% | — | Adobe Flash PlayerOpensuse EvergreenAdobe AIRAdobe AIR SDK+1 | 14/8/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different… | |
| Modificada | Alta (10) | 51% | — | Adobe Flash PlayerAdobe AIRAdobe AIR SDKAdobe AIR SDK & Compiler+1 | 14/8/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than… | |
| Modificada | Alta (10) | 51% | — | Adobe Flash PlayerOpensuse EvergreenAdobe AIRAdobe AIR SDK+1 | 14/8/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than… | |
| Modificada | Alta (10) | 51% | — | Adobe Flash PlayerAdobe AIRAdobe AIR SDKAdobe AIR SDK & Compiler+1 | 14/8/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than… | |
| Modificada | Alta (10) | 50% | — | Opensuse EvergreenAdobe Flash PlayerAdobe AIRAdobe AIR SDK+1 | 14/8/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different… | |
| Modificada | Alta (10) | 10% | — | Adobe Flash PlayerAdobe AIRAdobe AIR SDKAdobe AIR SDK & Compiler+1 | 14/8/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different… | |
| Modificada | Alta (10) | 50% | — | Adobe Flash PlayerOpensuse EvergreenAdobe AIRAdobe AIR SDK+1 | 14/8/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different… | |
| Modificada | Alta (10) | 5.7% | — | Adobe AIRAdobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash Player+1 | 14/8/2015 | 17/6/2026 | Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to cause a denial of service (vector-length corruption) or possibly have unspecified other impact via… | |
| Modificada | Alta (10) | 6.9% | — | Adobe AIRAdobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash Player+1 | 20/7/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory… | |
| Analizada | Crítica (9.8) | 19% | ⚠ Explotación activa | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Workstation+5 | 14/7/2015 | 17/6/2026 | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Adobe Flash PlayerAdobe Flash Player Desktop RuntimeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 14/7/2015 | 17/6/2026 | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote… |