Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.96%—Teleadapt Roomcast Ta-2400 Firmware27/7/202317/6/2026
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
ModificadaCrítica (9.8)1.0%—Teleadapt Roomcast Ta-2400 Firmware27/7/202317/6/2026
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available.
ModificadaAlta (7.5)0.53%—Teleadapt Roomcast Ta-2400 Firmware27/7/202317/6/2026
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe.
AnalizadaAlta (8.8)0.69%—HazelcastHazelcast Imdg18/7/202317/6/2026
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
ModificadaMedia (5.3)0.77%—Bouncycastle Bc-java5/7/202317/6/2026
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP…
ModificadaMedia (6.1)0.35%—Bund BKG Professional Ntripcaster28/6/202317/6/2026
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
ModificadaMedia (6.5)1.4%💥 ExploitOwncast Project Owncast10/6/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.
ModificadaMedia (5.7)0.34%—Dbbroadcast SFT DAB 600/c BiosDbbroadcast SFT DAB 600/c Firmware6/6/202317/6/2026
Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55 uc: 6.15 allows attackers on the same network to bypass authentication by re-using the IP address assigned to the device by the NAT protocol.
ModificadaCrítica (9)45%—Xfinity Comcast Defined Technologies Microeisbss2/6/202317/6/2026
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
ModificadaAlta (8.8)0.27%—Podlove Podcast Publisher23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.
ModificadaMedia (4.3)0.72%—Hazelcast22/5/202317/6/2026
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
ModificadaCrítica (9.8)0.79%—Azuracast5/5/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
ModificadaMedia (4.8)0.50%—Azuracast20/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.
ModificadaMedia (4.8)0.39%—Podlove Podcast Publisher7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions.
ModificadaMedia (5.4)0.53%—Castos Seriously Simple Podcasting16/1/202317/6/2026
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaCrítica (9.1)1.0%—HazelcastHazelcast-jet29/12/202217/6/2026
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet…
ModificadaCrítica (9.8)0.98%—Owncast Project Owncast29/11/202217/6/2026
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
ModificadaMedia (6.1)0.38%—Apereo Opencast28/11/202217/6/2026
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella authentication page could be used to redirect to an arbitrary URL for authenticated users. The vulnerability allows attackers to redirect users to sites outside of one's…
ModificadaMedia (5.5)0.43%—Bouncycastle Fips Java API21/11/202217/6/2026
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or…
ModificadaAlta (7.5)0.70%—Bund BKG Professional Ntripcaster17/11/202217/6/2026
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only…
ModificadaMedia (4.3)0.37%—Castos Seriously Simple Podcasting23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change.
ModificadaMedia (4.8)0.55%—Wp-forecast Project Wp-forecast9/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at WordPress.
ModificadaMedia (4.6)0.16%—Dominionvoting Imagecast X24/6/202217/6/2026
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of ballots without authorization.
ModificadaAlta (7.6)0.29%—Dominionvoting Imagecast X24/6/202217/6/2026
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive information and perform privileged…
ModificadaMedia (6.8)0.29%—Dominionvoting Imagecast X24/6/202217/6/2026
The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker with physical access may use this to gain administrative privileges on a device and install malicious code or perform arbitrary administrative actions.
Orbitaley — Vulnerabilidades