Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.17%—UnifierAIUnifier CastAI31/5/202417/6/2026
Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.
AplazadaAlta (8.8)0.69%—Miguelcastillo BIT LoaderAI20/5/202417/6/2026
A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.
AplazadaAlta (7.5)1.2%💥 PoCStakater ForecastleAI15/5/202417/6/2026
Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.
ModificadaMedia (4.3)0.45%—Podlove Podcast Publisher14/5/202417/6/2026
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
AplazadaAlta (7.5)0.75%—Bouncycastle Bouncy CastleAI14/5/202417/6/2026
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.
AplazadaMedia (5.9)0.90%—Bouncycastle Java TLS APIAIBouncycastle Jsse ProviderAI14/5/202417/6/2026
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
AplazadaAlta (7.5)1.1%—Bouncycastle BC JavaAIBouncycastle BC Java LTSAIBouncycastle BC FJAAIBouncycastle BC C Sharp NETAI14/5/202417/6/2026
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
AplazadaBaja (2.2)0.34%—UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAIUI Unifi Connect Display CastAI+17/5/202417/6/2026
An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Connect Display…
AplazadaAlta (7.5)0.33%—UI Unifi Connect ApplicationAIUI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAI+17/5/202417/6/2026
An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect Application (Version 3.7.9 and earlier) UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier)…
AplazadaBaja (2.2)0.44%—UI Unifi Connect EV StationAIUI Unifi Connect EV Station PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access Reader PROAI+47/5/202417/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version 1.1.18 and earlier) UniFi Access G2 Reader…
AplazadaAlta (7.5)0.77%—Bouncycastle Bouncy Castle JavaAIBouncycastle BcjsseAIBouncycastle Bouncy Castle Fips JavaAI3/5/202417/6/2026
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with…
AplazadaCrítica (9.8)0.95%—Guangzhou Yingshi Electronic Technology Ncast YingshiAI29/4/202417/6/2026
Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.php backend function
ModificadaMedia (5.4)0.38%—Podlove Podcast Publisher24/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11.
AnalizadaMedia (6.5)0.97%—Owncast Project Owncast19/4/202417/6/2026
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete custom emojis, which are saved on disk. The parameter name is taken…
AplazadaAlta (8.8)0.79%💥 PoCShibang Communications IP Network Intercom Broadcasting SystemAI17/4/202417/6/2026
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
ModificadaAlta (8.8)0.96%—Podlove Podcast Publisher15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12.
ModificadaAlta (7.5)0.55%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast10/4/202417/6/2026
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.
AnalizadaCrítica (10)0.24%—Google Chromecast Firmware5/4/202417/6/2026
u-boot bug that allows for u-boot shell and interrupt over UART
AplazadaMedia (5.4)0.65%—Shibang Communications IP Network Intercom Broadcasting SystemAI3/4/202417/6/2026
A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the argument jsondata[callee]/jsondata[imagename] leads to path traversal: '../filedir'. It is possible…
ModificadaMedia (5.4)0.34%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
ModificadaAlta (7.6)0.48%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast29/3/202417/6/2026
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
ModificadaMedia (5.4)0.35%—Tuxlog Wp-forecast29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2.
ModificadaMedia (6.1)0.43%—Castos Seriously Simple Podcasting28/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting.This issue affects Seriously Simple Podcasting: from n/a through <= 3.0.2.
ModificadaMedia (6.1)0.40%—Podlove Podcast Publisher27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through 4.0.9.
AnalizadaCrítica (9.1)0.41%—Owncast Project Owncast20/3/202417/6/2026
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit…
Orbitaley — Vulnerabilidades