Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.16%—Intel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i5inh Firmware19/1/202417/6/2026
Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.15%—Intel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i7inh Firmware19/1/202417/6/2026
Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.62%—Ari-soft ARI Stream Quiz31/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.
ModificadaMedia (6.5)0.65%—XWP Stream19/12/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
ModificadaAlta (7.5)0.73%—Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+118/12/202317/6/2026
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
ModificadaAlta (7.2)2.3%—Apache Streampark15/12/202317/6/2026
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark…
ModificadaMedia (4.9)0.85%—Apache Streampark15/12/202317/6/2026
In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive illegal parameters, leading to SQL…
ModificadaAlta (7.6)0.79%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+414/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client.…
ModificadaAlta (8.8)1.7%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+314/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server…
ModificadaAlta (8.8)1.7%—Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+314/12/202317/6/2026
Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server…
ModificadaMedia (5.4)0.38%—Ari-soft ARI Stream Quiz23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.2.32 versions.
ModificadaAlta (8.8)0.31%—Wpstream22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions.
ModificadaCrítica (9.8)15%—Qnap QTSQnap Multimedia ConsoleQnap Media Streaming Add-on3/11/202317/6/2026
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later Multimedia…
ModificadaCrítica (9.8)0.27%—Mlsoft Tco!stream30/10/202317/6/2026
In MLSoft TCO!stream versions 8.0.22.1115 and below, a vulnerability exists due to insufficient permission validation. This allows an attacker to make the victim download and execute arbitrary files.
ModificadaAlta (7.8)0.18%—HP Desktop PRO A 300 G3 FirmwareHP Desktop PRO A G3 FirmwareHP Desktop PRO A G3 Microtower FirmwareHP Zhan 66 PRO A G1 R Microtower Firmware+8518/10/202317/6/2026
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5.5)0.44%—Squareup OkhttpRedhat A-mq Streams27/9/202323/6/2026
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
ModificadaAlta (8.8)0.70%—Knowstreaming Project Knowstreaming5/9/202317/6/2026
KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role.
ModificadaMedia (4.8)0.44%—Mrdemonwolf Livestream Notice30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions.
ModificadaAlta (7.8)0.19%—Intel Easy Streaming Wizard11/8/202317/6/2026
Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.25%—Wpstream27/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream wpstream allows Cross Site Request Forgery.This issue affects WpStream: from n/a through <= 4.5.4.
ModificadaMedia (4.9)0.46%—Dell ECS Streamer26/7/202317/6/2026
Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious high-privileged user could potentially exploit this vulnerability leading to exposure of this sensitive data.
ModificadaAlta (8.8)1.1%—Apache Streampipes23/6/202317/6/2026
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0.
ModificadaMedia (4.8)0.37%—Grade Review Stream22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grade Us, Inc. Review Stream plugin <= 1.6.5 versions.
ModificadaCrítica (9.9)0.33%—Splunk APP FOR Stream1/6/202317/6/2026
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.
Orbitaley — Vulnerabilidades