Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which is later used in the `eval()` function on line 126, leading to remote code… | |
| Modificada | Crítica (9.8) | 1.3% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 1345, leading to remote code execution.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 493, leading to remote code execution. Commit… | |
| Modificada | Crítica (9.8) | 1.4% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 435, leading to remote code execution. Commit… | |
| Modificada | Crítica (9.8) | 1.4% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 395, leading to remote code… | |
| Modificada | Crítica (9.8) | 1.4% | — | Opengeos Streamlit-geospatial | 26/7/2024 | 17/6/2026 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to remote code execution. Commit… | |
| Modificada | Media (6.7) | 0.38% | — | Gstreamer ORC | 26/7/2024 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI… | |
| Analizada | Crítica (9.1) | 0.79% | — | Apache Streampark | 23/7/2024 | 17/6/2026 | On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout. Mitigation: all users should upgrade to 2.1.4 | |
| Modificada | Media (6.5) | 0.73% | — | Apache Streampark | 22/7/2024 | 17/6/2026 | On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | |
| Modificada | Alta (8.8) | 1.2% | — | Apache Streampark | 18/7/2024 | 17/6/2026 | On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users should upgrade to 2.1.4 | |
| Analizada | Media (5.9) | 0.28% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. Mitigation: all users… | |
| Modificada | Alta (8.8) | 1.1% | — | Apache Streampipes | 17/7/2024 | 17/6/2026 | Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0.… | |
| Modificada | Media (4.3) | 0.74% | — | Apache Streampipes | 17/7/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements. These endpoints were not properly validated, allowing an attacker to get… | |
| Modificada | Baja (3.7) | 0.66% | — | Apache Streampipes | 17/7/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, creating many identical users and corrupting StreamPipe's… | |
| Modificada | Media (4.7) | 1.1% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level… | |
| Modificada | Media (4.7) | 1.6% | — | Apache Streampark | 17/7/2024 | 17/6/2026 | In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level… | |
| Analizada | Alta (8.1) | 0.64% | — | Apache Streampark | 16/7/2024 | 17/6/2026 | In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is a risk of SQL injection vulnerability. The attacker must… | |
| Aplazada | Media (6.3) | 0.48% | — | Nats ServerAINats Streaming ServerAI | 11/7/2024 | 17/6/2026 | NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied… | |
| Modificada | Crítica (9.8) | 27% | — | Grandstream Gxp2135 Firmware | 3/7/2024 | 17/6/2026 | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. | |
| Analizada | Crítica (9.1) | 6.0% | 💥 Exploit | Apache Streampipes | 24/6/2024 | 17/6/2026 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache… | |
| Aplazada | Media (4) | 0.16% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC. | |
| Aplazada | Media (6.3) | 0.22% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed. | |
| Analizada | Alta (8.8) | 1.6% | — | Gstreamer | 7/6/2024 | 17/6/2026 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… |