Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.31% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code. | |
| Modificada | Media (6.8) | 0.38% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCast X devices from the EMS. | |
| Modificada | Media (6.8) | 0.28% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code. | |
| Modificada | Media (6.8) | 0.28% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code. | |
| Modificada | Media (4.6) | 0.23% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device. | |
| Modificada | Media (6.8) | 0.14% | — | Dominionvoting Imagecast X | 24/6/2022 | 17/6/2026 | The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the manufacturer to detect tampering. An… | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Media (6.5) | 1.0% | — | Nokia Broadcast Message Center | 25/5/2022 | 17/6/2026 | Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and… | |
| Modificada | Media (5.4) | 0.60% | — | Apereo Opencast | 24/5/2022 | 17/6/2026 | Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass along URLs for files belonging to organizations other than the user's own, which Opencast would then import into the current organization, bypassing organizational… | |
| Modificada | Alta (7.5) | 0.85% | — | Redhat Apicast | 27/4/2022 | 17/6/2026 | A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address. | |
| Modificada | Alta (7.2) | 1.5% | — | Secondlinethemes Podcast Importer Secondline | 11/4/2022 | 17/6/2026 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file | |
| Modificada | Media (4.9) | 0.81% | — | Mimecast Email Security | 16/3/2022 | 17/6/2026 | Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.) | |
| Modificada | Crítica (9.8) | 2.8% | 💥 PoC | Hazelcast | 3/3/2022 | 17/6/2026 | Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. | |
| Modificada | Alta (7.7) | 2.0% | 💥 PoC | Apereo Opencast | 14/12/2021 | 17/6/2026 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast… | |
| Modificada | Media (6.1) | 0.77% | — | Owncast Project Owncast | 14/12/2021 | 17/6/2026 | Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy and specifying the script-src. The worker-src is required to be… | |
| Modificada | Media (6.5) | 1.5% | — | Apereo Opencast | 14/12/2021 | 17/6/2026 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP form to send DELETE requests. This bypasses… | |
| Modificada | Media (4.8) | 0.64% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 1/11/2021 | 17/6/2026 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.62% | — | Secondlinethemes Podcast Subscribe Buttons | 18/10/2021 | 17/6/2026 | The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS. | |
| Modificada | Media (5.4) | 0.58% | — | Bplugins Streamcast Radio Player | 18/10/2021 | 17/6/2026 | The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Podlove Podcast Publisher | 27/9/2021 | 17/6/2026 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi. | |
| Modificada | Alta (8.8) | 2.4% | — | Electronjs Poddycast | 3/8/2021 | 17/6/2026 | Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of… | |
| Modificada | Alta (7.5) | 1.7% | — | Podcast Importer Secondline | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page. | |
| Modificada | Media (6.5) | 1.3% | — | Apereo Opencast | 16/6/2021 | 17/6/2026 | Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) denial of service attack, essentially taking down Opencast using a single HTTP… | |
| Modificada | Media (5.9) | 1.5% | — | Bouncycastle Bc-csharpBouncycastle Bouncy Castle Fips .net APIBouncycastle Fips Java APIBouncycastle THE Bouncy Castle Crypto Package FOR Java | 20/5/2021 | 17/6/2026 | Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic… | |
| Modificada | Media (5.4) | 0.71% | — | Apereo Opencast | 18/2/2021 | 17/6/2026 | Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with strict access rules will overwrite the currently set series access. This allows for an easy denial of access for all… |