Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.17% | — | UnifierAIUnifier CastAI | 31/5/2024 | 17/6/2026 | Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted. | |
| Aplazada | Alta (8.8) | 0.69% | — | Miguelcastillo BIT LoaderAI | 20/5/2024 | 17/6/2026 | A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js. | |
| Aplazada | Alta (7.5) | 1.2% | 💥 PoC | Stakater ForecastleAI | 15/5/2024 | 17/6/2026 | Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component. | |
| Modificada | Media (4.3) | 0.45% | — | Podlove Podcast Publisher | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14. | |
| Aplazada | Alta (7.5) | 0.75% | — | Bouncycastle Bouncy CastleAI | 14/5/2024 | 17/6/2026 | An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. | |
| Aplazada | Media (5.9) | 0.90% | — | Bouncycastle Java TLS APIAIBouncycastle Jsse ProviderAI | 14/5/2024 | 17/6/2026 | An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. | |
| Aplazada | Alta (7.5) | 1.1% | — | Bouncycastle BC JavaAIBouncycastle BC Java LTSAIBouncycastle BC FJAAIBouncycastle BC C Sharp NETAI | 14/5/2024 | 17/6/2026 | An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. | |
| Aplazada | Baja (2.2) | 0.34% | — | UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAIUI Unifi Connect Display CastAI+1 | 7/5/2024 | 17/6/2026 | An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Connect Display… | |
| Aplazada | Alta (7.5) | 0.33% | — | UI Unifi Connect ApplicationAIUI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAI+1 | 7/5/2024 | 17/6/2026 | An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect Application (Version 3.7.9 and earlier) UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier)… | |
| Aplazada | Baja (2.2) | 0.44% | — | UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access Reader PROAI+4 | 7/5/2024 | 17/6/2026 | An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Access G2 Reader… | |
| Aplazada | Alta (7.5) | 0.77% | — | Bouncycastle Bouncy Castle JavaAIBouncycastle BcjsseAIBouncycastle Bouncy Castle Fips JavaAI | 3/5/2024 | 17/6/2026 | An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Guangzhou Yingshi Electronic Technology Ncast YingshiAI | 29/4/2024 | 17/6/2026 | Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.php backend function | |
| Modificada | Media (5.4) | 0.38% | — | Podlove Podcast Publisher | 24/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11. | |
| Analizada | Media (6.5) | 0.97% | — | Owncast Project Owncast | 19/4/2024 | 17/6/2026 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete custom emojis, which are saved on disk. The parameter name is taken… | |
| Aplazada | Alta (8.8) | 0.79% | 💥 PoC | Shibang Communications IP Network Intercom Broadcasting SystemAI | 17/4/2024 | 17/6/2026 | File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component. | |
| Modificada | Alta (8.8) | 0.96% | — | Podlove Podcast Publisher | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12. | |
| Modificada | Alta (7.5) | 0.55% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1. | |
| Analizada | Crítica (10) | 0.24% | — | Google Chromecast Firmware | 5/4/2024 | 17/6/2026 | u-boot bug that allows for u-boot shell and interrupt over UART | |
| Aplazada | Media (5.4) | 0.65% | — | Shibang Communications IP Network Intercom Broadcasting SystemAI | 3/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible… | |
| Modificada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Modificada | Alta (7.6) | 0.48% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Modificada | Media (5.4) | 0.35% | — | Tuxlog Wp-forecast | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2. | |
| Modificada | Media (6.1) | 0.43% | — | Castos Seriously Simple Podcasting | 28/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting.This issue affects Seriously Simple Podcasting: from n/a through <= 3.0.2. | |
| Modificada | Media (6.1) | 0.40% | — | Podlove Podcast Publisher | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9. | |
| Analizada | Crítica (9.1) | 0.41% | — | Owncast Project Owncast | 20/3/2024 | 17/6/2026 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit… |