Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.96% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. | |
| Modificada | Crítica (9.8) | 1.0% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available. | |
| Modificada | Alta (7.5) | 0.53% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe. | |
| Analizada | Alta (8.8) | 0.69% | — | HazelcastHazelcast Imdg | 18/7/2023 | 17/6/2026 | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted. | |
| Modificada | Media (5.3) | 0.77% | — | Bouncycastle Bc-java | 5/7/2023 | 17/6/2026 | Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP… | |
| Modificada | Media (6.1) | 0.35% | — | Bund BKG Professional Ntripcaster | 28/6/2023 | 17/6/2026 | Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44 | |
| Modificada | Media (6.5) | 1.4% | 💥 Exploit | Owncast Project Owncast | 10/6/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. | |
| Modificada | Media (5.7) | 0.34% | — | Dbbroadcast SFT DAB 600/c BiosDbbroadcast SFT DAB 600/c Firmware | 6/6/2023 | 17/6/2026 | Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55 uc: 6.15 allows attackers on the same network to bypass authentication by re-using the IP address assigned to the device by the NAT protocol. | |
| Modificada | Crítica (9) | 45% | — | Xfinity Comcast Defined Technologies Microeisbss | 2/6/2023 | 17/6/2026 | An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation.. | |
| Modificada | Alta (8.8) | 0.27% | — | Podlove Podcast Publisher | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions. | |
| Modificada | Media (4.3) | 0.72% | — | Hazelcast | 22/5/2023 | 17/6/2026 | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets. | |
| Modificada | Crítica (9.8) | 0.79% | — | Azuracast | 5/5/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3. | |
| Modificada | Media (4.8) | 0.50% | — | Azuracast | 20/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18. | |
| Modificada | Media (4.8) | 0.39% | — | Podlove Podcast Publisher | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Castos Seriously Simple Podcasting | 16/1/2023 | 17/6/2026 | The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Crítica (9.1) | 1.0% | — | HazelcastHazelcast-jet | 29/12/2022 | 17/6/2026 | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet… | |
| Modificada | Crítica (9.8) | 0.98% | — | Owncast Project Owncast | 29/11/2022 | 17/6/2026 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | |
| Modificada | Media (6.1) | 0.38% | — | Apereo Opencast | 28/11/2022 | 17/6/2026 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella authentication page could be used to redirect to an arbitrary URL for authenticated users. The vulnerability allows attackers to redirect users to sites outside of one's… | |
| Modificada | Media (5.5) | 0.43% | — | Bouncycastle Fips Java API | 21/11/2022 | 17/6/2026 | An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or… | |
| Modificada | Alta (7.5) | 0.70% | — | Bund BKG Professional Ntripcaster | 17/11/2022 | 17/6/2026 | BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only… | |
| Modificada | Media (4.3) | 0.37% | — | Castos Seriously Simple Podcasting | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change. | |
| Modificada | Media (4.8) | 0.55% | — | Wp-forecast Project Wp-forecast | 9/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress. | |
| Modificada | Media (4.6) | 0.16% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of ballots without authorization. | |
| Modificada | Alta (7.6) | 0.29% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive information and perform privileged… | |
| Modificada | Media (6.8) | 0.29% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker with physical access may use this to gain administrative privileges on a device and install malicious code or perform arbitrary administrative actions. |