Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.3% | — | Panasonic System Interface Device 0021Panasonic System Interface Device 0040 | 9/1/2019 | 17/6/2026 | An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute… | |
| Modificada | Media (6.8) | 1.1% | — | Panasonic Bn-sdwbp3 Firmware | 9/1/2019 | 17/6/2026 | Buffer overflow in BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 0.60% | — | Panasonic Bn-sdwbp3 Firmware | 9/1/2019 | 17/6/2026 | BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.62% | — | Panasonic Bn-sdwbp3 Firmware | 9/1/2019 | 17/6/2026 | BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors. | |
| Modificada | Alta (8) | 0.42% | — | Subsonic | 19/12/2018 | 17/6/2026 | Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user's session, or… | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabilities in the c0-param2, c0-param3, and c0-param4 parameters to dwr/call/plaincall/tagService.setTags.dwr that could be used to steal session information of a victim. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabilities in the title and subtitle parameters to generalSettings.view that could be used to steal session information of a victim. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerabilities in the name[x], sourceformats[x], targetFormat[x], step1[x], and step2[x] parameters (where x is an integer) to transcodingSettings.view that could be used to steal session information… | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabilities in the name[x], streamUrl[x], homepageUrl[x] parameters (where x is an integer) to internetRadioSettings.view that could be used to steal session information of a victim. | |
| Modificada | Media (5.9) | 0.91% | — | Subsonic Music Streamer | 11/9/2018 | 17/6/2026 | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data. | |
| Modificada | Media (5.9) | 0.54% | — | Dsub FOR Subsonic Project Dsub FOR Subsonic | 6/9/2018 | 17/6/2026 | daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim… | |
| Modificada | Crítica (9.8) | 4.5% | — | Sonicwall Global Management System | 3/8/2018 | 17/6/2026 | A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Iscripts Sonicbb | 4/4/2018 | 17/6/2026 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | Subsonic | 5/2/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other impact via the name parameter to… | |
| Modificada | Media (6.5) | 1.2% | — | Subsonic | 23/1/2018 | 17/6/2026 | Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data. | |
| Modificada | Media (5.4) | 0.71% | — | Sonicwall AnalyzerSonicwall Global Management System | 14/1/2018 | 17/6/2026 | SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module. | |
| Modificada | Media (5.4) | 2.5% | — | Sonicwall Sonicos | 8/1/2018 | 17/6/2026 | SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens. | |
| Modificada | Media (5.4) | 2.5% | — | Sonicwall Sonicos | 8/1/2018 | 17/6/2026 | SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens. | |
| Modificada | Alta (8.8) | 1.2% | — | Panasonic Kx-hjb1000 Firmware | 20/10/2017 | 17/6/2026 | SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Panasonic Kx-hjb1000 Firmware | 20/10/2017 | 17/6/2026 | Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary files in a specific directory via unspecified vectors. | |
| Modificada | Media (5.3) | 1.2% | — | Panasonic Kx-hjb1000 Firmware | 20/10/2017 | 17/6/2026 | Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configuration menu via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.8% | 💥 Exploit | Subsonic | 25/7/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Internet Radio Settings via the… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Subsonic | 21/7/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view. |