Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.36% | — | Ari-soft ARI Stream QuizAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2. | |
| Aplazada | Media (5.1) | 1.9% | — | Huashi Private Cloud CDN Live Streaming Acceleration ServerAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack… | |
| Analizada | Alta (7.8) | 1.6% | — | GstreamerDebian Linux | 22/5/2024 | 17/6/2026 | GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (8.8) | 1.5% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Media (6.6) | 1.2% | — | Qnap Media Streaming Add-on | 3/5/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and… | |
| Modificada | Alta (8.8) | 1.7% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (8.8) | 2.2% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 2.3% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 2.1% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 2.1% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (8.8) | 1.4% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (8.8) | 1.5% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 1.6% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 2.1% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 1.7% | — | Gstreamer | 3/5/2024 | 17/6/2026 | GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Aplazada | Alta (8.8) | 0.88% | — | Grandstream Ucm6202AIGrandstream Ucm6204AIGrandstream Ucm6208AIGrandstream Ucm6510AI | 29/4/2024 | 17/6/2026 | The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected… | |
| Analizada | Crítica (9.8) | 0.54% | — | Qnap Media Streaming Add-on | 26/4/2024 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 (… | |
| Aplazada | Media (5.3) | 0.55% | — | Streamweasels Twitch IntegrationAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StreamWeasels StreamWeasels Twitch Integration.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.8. | |
| Modificada | Crítica (9.8) | 1.3% | — | Videowhisper Live Streaming Integration | 3/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Huashi Private Cloud CDN Live Streaming Acceleration Server Hgateway-sixportAI | 29/3/2024 | 17/6/2026 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. | |
| Aplazada | Media (6.5) | 0.35% | — | Streamweasels Twitch IntegrationAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StreamWeasels StreamWeasels Twitch Integration allows Stored XSS.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.5. | |
| Modificada | Alta (8.8) | 0.22% | — | Ari-soft ARI Stream Quiz | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft ARI Stream Quiz.This issue affects ARI Stream Quiz: from n/a through 1.2.32. | |
| Aplazada | Alta (8.8) | 0.39% | — | Grandstream Gxp14xxAIGrandstream Gxp16xxAI | 9/3/2024 | 17/6/2026 | An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token. | |
| Analizada | Media (5.3) | 0.35% | — | Haivision MaanagerHaivision Streamhub | 28/2/2024 | 17/6/2026 | Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users. | |
| Analizada | Alta (7.8) | 0.18% | — | Splashtop Mirroring360 ReceiverSplashtop Mirroring360 SenderSplashtopSplashtop FOR RMM+1 | 25/1/2024 | 17/6/2026 | The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using… |