Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.71% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file. | |
| Analizada | Alta (8.2) | 1.00% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file. | |
| Analizada | Media (5.1) | 0.75% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system. | |
| Analizada | Alta (8.7) | 0.66% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts. | |
| Analizada | Crítica (9.4) | 0.50% | — | Wowza Streaming Engine | 21/11/2024 | 17/6/2026 | Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution. | |
| Aplazada | Media (6.4) | 0.41% | — | Streamweasels Online Status BARAI | 21/11/2024 | 17/6/2026 | The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Slickstream Engagement AND ConversionsAI | 12/11/2024 | 17/6/2026 | The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slick-grid shortcode in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.5) | 2.0% | — | XstreamAI | 8/11/2024 | 17/6/2026 | XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver.… | |
| Aplazada | Media (6.4) | 0.38% | — | Streamweasels Youtube IntegrationAI | 29/10/2024 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.38% | — | Streamweasels Kick IntegrationAI | 29/10/2024 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.5) | 0.44% | — | Telestream Sentry | 25/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter. | |
| Analizada | Media (5.3) | 0.39% | — | Telestream Sentry | 23/10/2024 | 17/6/2026 | A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.5) | 0.69% | — | Gstreamer Rtsp ServerAI | 22/10/2024 | 17/6/2026 | Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests. | |
| Analizada | Media (5.4) | 0.35% | — | Streamweasels Twitch Integration | 19/10/2024 | 17/6/2026 | The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-twitch-embed shortcode in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.33% | — | XWP Stream | 13/9/2024 | 17/6/2026 | The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS… | |
| Aplazada | Media (5.9) | 0.27% | — | Bplugins StreamcastAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins StreamCast allows Stored XSS.This issue affects StreamCast: from n/a through 2.2.3. | |
| Analizada | Media (6.5) | 0.57% | — | Snowflake Streamlit | 12/8/2024 | 17/6/2026 | Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is… | |
| Modificada | Media (5.3) | 0.21% | — | Litestream | 31/7/2024 | 17/6/2026 | An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack. | |
| Analizada | Alta (7.8) | 0.15% | — | Splashtop Streamer | 28/7/2024 | 17/6/2026 | The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a version.dll file in the folder. | |
| Modificada | Alta (7.8) | 0.21% | — | Splashtop Streamer | 28/7/2024 | 17/6/2026 | The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder. | |
| Analizada | Alta (7.8) | 0.15% | — | Splashtop Streamer | 28/7/2024 | 17/6/2026 | The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg. | |
| Analizada | Alta (7) | 0.14% | — | Splashtop Streamer | 28/7/2024 | 17/6/2026 | The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg. | |
| Modificada | Crítica (9.8) | 0.79% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which is later passed to the `gpd.read_file` method. `gpd.read_file` method creates a… | |
| Modificada | Crítica (9.8) | 1.4% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_🏜️_Raster_Data_Visualization.py` takes user input, which is later used in the `eval()` function on line 86, leading to remote code… | |
| Modificada | Crítica (9.8) | 0.71% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 47 of `pages/7_📦_Web_Map_Service.py` takes user input, which is passed to `get_layers` function, in which `url` is used with `get_wms_layer` method.… |