Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection. | |
| Modificada | Alta (7.5) | 1.8% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction. | |
| Modificada | Alta (7.5) | 1.5% | — | Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+386 | 26/6/2018 | 17/6/2026 | There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar. | |
| Modificada | Media (6.5) | 1.0% | — | Silkypress Image Zoom | 26/6/2018 | 17/6/2026 | WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of service. This attack appear to be exploitable via Can be triggered intentionally (or unintentionally via CSRF) by any logged in user. This vulnerability appears to have… | |
| Modificada | Media (4.6) | 0.39% | — | Bostonscientific Zoom Latitude PRM 3120 Firmware | 1/5/2018 | 17/6/2026 | Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. | |
| Modificada | Media (4.6) | 0.28% | — | Bostonscientific Zoom Latitude PRM 3120 Firmware | 1/5/2018 | 17/6/2026 | Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Zoom | 19/12/2017 | 17/6/2026 | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | |
| Modificada | Alta (8.8) | 10% | 💥 Exploit | Zoom | 19/12/2017 | 17/6/2026 | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler. | |
| Modificada | Alta (8.8) | 1.7% | — | Summerinfant Baby Zoom Wifi Monitor Firmware | 10/4/2017 | 17/6/2026 | Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL. | |
| Modificada | Crítica (9.8) | 2.3% | — | Summerinfant Baby Zoom Wifi Monitor Firmware | 10/4/2017 | 17/6/2026 | Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service. | |
| Modificada | Media (4.3) | 8.8% | 💥 Exploit | Digitalzoomstudio Video Gallery | 26/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter. | |
| Modificada | Media (5.4) | 0.34% | — | Zoom Cloud Meetings | 9/9/2014 | 17/6/2026 | The ZOOM Cloud Meetings (aka us.zoom.videomeetings) application @7F060008 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Digitalzoomstudio Video Gallery | 30/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or (4) preview_skin_overlay.swf in… | |
| Modificada | Media (6.8) | 2.7% | — | Inmatrix Zoom Player | 3/3/2014 | 16/6/2026 | Heap-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code via a large biClrUsed value in a BMP file. | |
| Modificada | Media (6.8) | 3.0% | — | Inmatrix Zoom Player | 3/3/2014 | 16/6/2026 | Stack-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code via a large biClrUsed value in a BMP file. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Mikedeboer COM Zoom | 30/12/2009 | 16/6/2026 | SQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | |
| Modificada | Media (4.3) | 1.3% | — | Karim Ratib Zoomify | 9/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the node title. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Inmatrix Zoom Player | 27/12/2007 | 16/6/2026 | Buffer overflow in Zoom Player 6.00 beta 2 and earlier allows user-assisted remote attackers to execute arbitrary code via an HTTP link to a PLS file in a crafted ZPL file, which causes an overflow in Unicode handling when generating an error message. | |
| Modificada | Media (6.8) | 1.2% | — | AC Zoom Blockhosts | 14/8/2007 | 16/6/2026 | BlockHosts before 2.0.4 does not properly parse (1) sshd and (2) vsftpd log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by connecting through ssh with a client… | |
| Modificada | Alta (7.5) | 1.1% | — | Vbzoom | 5/7/2007 | 16/6/2026 | SQL injection vulnerability in reply.php in VBZooM 1.12 allows remote attackers to execute arbitrary SQL commands via the UserID parameter to sub-join.php. NOTE: this may be the same as CVE-2006-3691.4. | |
| Modificada | Alta (9.3) | 6.5% | — | Zoomify Viewer Activex Control | 11/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors. |