Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.16% | — | Intel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i5inh Firmware | 19/1/2024 | 17/6/2026 | Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i7inh Firmware | 19/1/2024 | 17/6/2026 | Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.62% | — | Ari-soft ARI Stream Quiz | 31/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0. | |
| Modificada | Media (6.5) | 0.65% | — | XWP Stream | 19/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2. | |
| Modificada | Alta (7.5) | 0.73% | — | Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+1 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. | |
| Modificada | Alta (7.2) | 2.3% | — | Apache Streampark | 15/12/2023 | 17/6/2026 | In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark… | |
| Modificada | Media (4.9) | 0.85% | — | Apache Streampark | 15/12/2023 | 17/6/2026 | In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive illegal parameters, leading to SQL… | |
| Modificada | Alta (7.6) | 0.79% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+4 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client.… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Media (5.4) | 0.38% | — | Ari-soft ARI Stream Quiz | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.2.32 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpstream | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions. | |
| Modificada | Crítica (9.8) | 15% | — | Qnap QTSQnap Multimedia ConsoleQnap Media Streaming Add-on | 3/11/2023 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia… | |
| Modificada | Crítica (9.8) | 0.27% | — | Mlsoft Tco!stream | 30/10/2023 | 17/6/2026 | In MLSoft TCO!stream versions 8.0.22.1115 and below, a vulnerability exists due to insufficient permission validation. This allows an attacker to make the victim download and execute arbitrary files. | |
| Modificada | Alta (7.8) | 0.18% | — | HP Desktop PRO A 300 G3 FirmwareHP Desktop PRO A G3 FirmwareHP Desktop PRO A G3 Microtower FirmwareHP Zhan 66 PRO A G1 R Microtower Firmware+85 | 18/10/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.5) | 0.44% | — | Squareup OkhttpRedhat A-mq Streams | 27/9/2023 | 23/6/2026 | A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions. | |
| Modificada | Alta (8.8) | 0.70% | — | Knowstreaming Project Knowstreaming | 5/9/2023 | 17/6/2026 | KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role. | |
| Modificada | Media (4.8) | 0.44% | — | Mrdemonwolf Livestream Notice | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Easy Streaming Wizard | 11/8/2023 | 17/6/2026 | Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpstream | 27/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream wpstream allows Cross Site Request Forgery.This issue affects WpStream: from n/a through <= 4.5.4. | |
| Modificada | Media (4.9) | 0.46% | — | Dell ECS Streamer | 26/7/2023 | 17/6/2026 | Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious high-privileged user could potentially exploit this vulnerability leading to exposure of this sensitive data. | |
| Modificada | Alta (8.8) | 1.1% | — | Apache Streampipes | 23/6/2023 | 17/6/2026 | A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0. | |
| Modificada | Media (4.8) | 0.37% | — | Grade Review Stream | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grade Us, Inc. Review Stream plugin <= 1.6.5 versions. | |
| Modificada | Crítica (9.9) | 0.33% | — | Splunk APP FOR Stream | 1/6/2023 | 17/6/2026 | In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user. |