Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)7.2%💥 PoCBouncycastle Bc-javaApache KarafOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+1618/12/202017/6/2026
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
ModificadaMedia (4.8)0.28%—Apereo Opencast8/12/202017/6/2026
Opencast before versions 8.9 and 7.9 disables HTTPS hostname verification of its HTTP client used for a large portion of Opencast's HTTP requests. Hostname verification is an important part when using HTTPS to ensure that the presented certificate is valid for the host. Disabling it can allow for man-in-the-middle…
ModificadaCrítica (9.8)1.6%—HazelcastHazelcast JET9/11/202017/6/2026
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
ModificadaMedia (5.3)0.92%—Bouncycastle Fips Java APIBouncycastle Legion-of-the-bouncy-castle2/11/202017/6/2026
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short…
ModificadaMedia (6.5)0.48%—Actions-micro Ezcast PRO II Firmware16/10/202017/6/2026
In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device.
ModificadaCrítica (9.8)40%💥 ExploitSzuray Iptv/h.264 Video Encoder FirmwareSzuray Iptv/h.265 Video Encoder FirmwareJtechdigital H.264 Iptv Encoder 1080p@60hz FirmwareProvideoinstruments Vecaster-hd-h264 Firmware+36/10/202017/6/2026
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary…
ModificadaAlta (7.5)2.1%—Szuray Iptv/h.264 Video Encoder FirmwareSzuray Iptv/h.265 Video Encoder FirmwareJtechdigital H.264 Iptv Encoder 1080p@60hz FirmwareProvideoinstruments Vecaster-hd-h264 Firmware+36/10/202017/6/2026
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be private.
ModificadaCrítica (9.8)20%💥 ExploitSzuray Iptv/h.264 Video Encoder FirmwareSzuray Iptv/h.265 Video Encoder FirmwareJtechdigital H.264 Iptv Encoder 1080p@60hz FirmwareProvideoinstruments Vecaster-hd-h264 Firmware+36/10/202017/6/2026
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom…
ModificadaCrítica (9.8)35%💥 ExploitSzuray Iptv/h.264 Video Encoder FirmwareSzuray Iptv/h.265 Video Encoder FirmwareJtechdigital H.264 Iptv Encoder 1080p@60hz FirmwareProvideoinstruments Vecaster-hd-h264 Firmware+36/10/202017/6/2026
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute,…
ModificadaMedia (6.5)0.97%—Oracle Financial Services Loan Loss Forecasting AND Provisioning15/7/202017/6/2026
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaMedia (6.5)0.64%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request will succeed.
ModificadaAlta (8.1)1.1%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.
ModificadaMedia (6.5)1.2%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying…
ModificadaAlta (8.8)2.0%—Castel Nextgen DVR Firmware4/6/202017/6/2026
Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their…
ModificadaAlta (7.8)0.50%—Fazecast JserialcommSchneider-electric Ecostruxure IT Gateway14/5/202017/6/2026
In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7.1)1.1%—Oracle Financial Services Loan Loss Forecasting AND Provisioning15/4/202017/6/2026
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaAlta (7.5)0.72%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
ModificadaMedia (5.4)0.56%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
ModificadaAlta (7.5)1.4%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
ModificadaAlta (7.5)1.5%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
ModificadaAlta (8.8)0.51%—Castlerock Snmpc Online9/4/202017/6/2026
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
ModificadaMedia (6.5)0.63%—Apereo Opencast30/1/202017/6/2026
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security…
ModificadaCrítica (10)1.3%—Apereo Opencast30/1/202017/6/2026
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me…
ModificadaAlta (7.5)1.2%—Apereo Opencast30/1/202017/6/2026
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to…