Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.71%—Gvectors Wpforo15/6/202017/6/2026
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
ModificadaAlta (8.8)0.71%—Gvectors Wpforo15/6/202017/6/2026
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
ModificadaBaja (3.3)0.30%—Geovision Gv-gf192x Firmware12/6/202017/6/2026
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.
ModificadaMedia (5.9)0.51%—Usavisionsys Geovision Gv-as210 FirmwareUsavisionsys Geovision Gv-as410 FirmwareUsavisionsys Geovision Gv-as810 FirmwareUsavisionsys Geovision Gv-as1010 Firmware+112/6/202017/6/2026
GeoVision Door Access Control device family employs shared cryptographic private keys for SSH and HTTPS. Attackers may conduct MITM attack with the derived keys and plaintext recover of encrypted messages.
ModificadaCrítica (9.8)0.87%—Usavisionsys Geovision Gv-as210 FirmwareUsavisionsys Geovision Gv-as410 FirmwareUsavisionsys Geovision Gv-as810 FirmwareUsavisionsys Geovision Gv-as1010 Firmware+112/6/202017/6/2026
GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaAlta (7.5)1.1%—Honeywell H4d8pr1 FirmwareHoneywell Hfd5pr1 FirmwareHoneywell Hpw2p1 FirmwareHoneywell Hdzp304di Firmware+4431/10/201917/6/2026
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
ModificadaCrítica (9.8)1.4%—Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+6031/10/201917/6/2026
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
ModificadaMedia (5.4)1.1%—Shapepress WP Dsgvo Tools29/8/201917/6/2026
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
ModificadaAlta (7.5)1.9%—Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware29/8/201917/6/2026
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
ModificadaMedia (6.1)1.1%—Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware29/8/201917/6/2026
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
ModificadaCrítica (9.8)1.9%—Androvideo VD 1 FirmwareGeovision Gv-vr360 FirmwareGeovision Gv-vd8700 Firmware29/8/201917/6/2026
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.
ModificadaCrítica (9.8)2.7%—Gvectors Wpforo Forum19/6/201917/6/2026
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
ModificadaAlta (7.8)0.39%—Gnome Gvfs11/6/201917/6/2026
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a…
ModificadaMedia (5.7)1.8%—Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
ModificadaAlta (8.1)1.8%—Gnome Gvfs29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the admin backend doesn't implement query_info_on_read/write.
ModificadaAlta (7.3)1.8%—Gnome GvfsCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap29/5/201917/6/2026
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
ModificadaCrítica (9.8)15%💥 ExploitGrandstream Gac2500 FirmwareGrandstream Gvc3202 FirmwareGrandstream Gxv3275 FirmwareGrandstream Gxv3240 Firmware+130/3/201917/6/2026
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie…
ModificadaAlta (7)0.36%—Gnome Gvfs25/3/201917/6/2026
An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users…
ModificadaMedia (5.5)0.28%—Google Gvisor17/12/201817/6/2026
Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
ModificadaCrítica (9.8)0.81%—Google Gvisor17/11/201817/6/2026
pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled.
ModificadaMedia (6.8)0.45%—Google Gvisor2/9/201817/6/2026
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
ModificadaAlta (7.5)0.99%—Genesis Vision Gvtoken4/7/201817/6/2026
GVToken Genesis Vision (GVT) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.
ModificadaAlta (7.5)1.1%—GVE Globalvillage Ecosystem25/6/201817/6/2026
The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue.…
ModificadaMedia (6.1)3.6%💥 ExploitGvectors Wpforo Forum4/6/201817/6/2026
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.