Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.20%—Intel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i5inh Firmware11/11/202217/6/2026
Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)5.7%💥 ExploitGrandstream Gds3710 Firmware23/9/202217/6/2026
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit…
ModificadaCrítica (9.8)5.3%💥 ExploitGrandstream Gds3710 Firmware23/9/202217/6/2026
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
AnalizadaAlta (7.5)19%—XstreamFasterxml Woodstox16/9/202217/6/2026
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
AnalizadaAlta (7.5)2.2%—Xstream16/9/202217/6/2026
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
ModificadaMedia (6.7)0.33%💥 PoCRedhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+524/8/202217/6/2026
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
ModificadaAlta (7.3)0.40%—Logitech Streamlabs Desktop19/8/202217/6/2026
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.
ModificadaMedia (5.5)0.30%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cpp.
ModificadaMedia (5.5)0.30%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a segmentation violation via std::vector<unsigned int, std::allocator<unsigned int> >::size() const at /bits/stl_vector.h.
ModificadaMedia (5.5)0.30%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
ModificadaMedia (5.5)0.30%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a segmentation violation via getType() at /common/bbox.cpp.
ModificadaMedia (5.5)0.30%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a heap-buffer overflow via __asan_memmove at /asan/asan_interceptors_memintrinsics.cpp.
ModificadaMedia (5.5)0.32%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry().
ModificadaMedia (6.5)1.7%—Snowflake Streamlit1/8/202217/6/2026
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files, and potentially other sensitive…
ModificadaAlta (7.8)0.46%—GstreamerDebian Linux19/7/202217/6/2026
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap…
ModificadaAlta (7.8)0.46%—GstreamerDebian Linux19/7/202217/6/2026
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse…
ModificadaAlta (7.8)0.43%—GstreamerDebian Linux19/7/202217/6/2026
DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault…
ModificadaAlta (7.8)0.43%—GstreamerDebian Linux19/7/202217/6/2026
DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a…
ModificadaAlta (7.8)0.45%—GstreamerDebian Linux19/7/202217/6/2026
DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be…
ModificadaAlta (7.8)0.50%—GstreamerDebian Linux19/7/202217/6/2026
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
ModificadaAlta (7.8)0.50%—GstreamerDebian Linux19/7/202217/6/2026
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
ModificadaCrítica (9.3)1.3%—Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark11/7/202217/6/2026
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.6)1.2%—Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark11/7/202217/6/2026
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaMedia (6.5)0.95%—Jenkins Vmware Vrealize Codestream15/3/202217/6/2026
Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Orbitaley — Vulnerabilidades