Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)2.5%💥 ExploitCastos Seriously Simple Podcasting11/3/202417/6/2026
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
AnalizadaAlta (7.6)0.52%—Hazelcast28/2/202417/6/2026
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
AnalizadaMedia (6.5)0.54%—Hazelcast16/2/202417/6/2026
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
ModificadaMedia (5.3)0.52%—Podlove Podcast Publisher7/2/202417/6/2026
The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin's settings.
ModificadaMedia (5.3)0.55%—Podlove Podcast Publisher7/2/202417/6/2026
The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to export the plugin's tracking data and…
ModificadaMedia (5.5)0.16%—Spooncast Spoon24/1/202417/6/2026
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.
ModificadaCrítica (9.8)28%—Badaix Snapcast23/1/20249/7/2026
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
ModificadaAlta (7.5)67%💥 ExploitNcast Project Ncast8/1/202417/6/2026
A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely.…
ModificadaCrítica (9.8)89%💥 ExploitHikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has…
ModificadaMedia (6.5)0.98%—Hikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects an unknown part of the file access/html/system.html of the component Log File Handler. The manipulation leads to information disclosure. The exploit has been disclosed to…
ModificadaAlta (7.5)70%—Hikvision Intercom Broadcast System17/12/202317/6/2026
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to…
ModificadaAlta (7.5)0.83%—Apereo Opencast12/12/202317/6/2026
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
ModificadaCrítica (9.8)0.37%—Google Chromecast Firmware11/12/202317/6/2026
An oversight in BCB handling of reboot reason that allows for persistent code execution
ModificadaCrítica (9.8)0.37%—Google Chromecast Firmware11/12/202317/6/2026
U-Boot vulnerability resulting in persistent Code Execution
ModificadaCrítica (9.8)0.32%—Google Chromecast Firmware11/12/202317/6/2026
U-Boot shell vulnerability resulting in Privilege escalation in a production device
ModificadaCrítica (9.8)0.30%—Google Chromecast Firmware11/12/202317/6/2026
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
ModificadaCrítica (9.8)1.6%—Owncast Project Owncast27/11/202317/6/2026
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
ModificadaMedia (5.5)1.0%—Bouncycastle Bouncy Castle FOR JavaBouncycastle Fips Java API23/11/202317/6/2026
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through…
ModificadaCrítica (9.8)0.55%—Castos Seriously Simple Stats6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0.
ModificadaMedia (5.4)0.50%—Secondlinethemes Podcast Subscribe Buttons20/10/202317/6/2026
The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' shortcode in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (6.1)0.33%—Castos Seriously Simple Stats17/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions.
ModificadaMedia (5.4)0.38%—Jesweb Anchor Episodes Index (spotify FOR Podcasters)2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jesweb.Dev Anchor Episodes Index (Spotify for Podcasters) plugin <= 2.1.7 versions.
ModificadaAlta (7.5)0.65%—Redhat Apicast27/9/202317/6/2026
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorized information.
ModificadaMedia (6.1)1.4%💥 ExploitIcewarp Deep Castle G214/9/202317/6/2026
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
ModificadaCrítica (9.8)0.96%—Teleadapt Roomcast Ta-2400 Firmware27/7/202317/6/2026
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password).
Orbitaley — Vulnerabilidades