Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.0%—Synology Surveillance Station27/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
ModificadaAlta (8.8)0.59%—Limesurvey9/2/201817/6/2026
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET…
ModificadaCrítica (9.8)3.6%—Surveys Project Surveys14/9/201717/6/2026
Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.
ModificadaCrítica (9.8)3.6%—Surveys Project Surveys14/9/201717/6/2026
Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.
ModificadaCrítica (9.8)3.6%—Surveys Project Surveys14/9/201717/6/2026
Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.
ModificadaAlta (8.8)17%💥 ExploitNuuo Nvrmini 2Netgear Readynas Surveillance31/8/201617/6/2026
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command.
ModificadaAlta (8.8)14%💥 ExploitNuuo Nvrmini 2Netgear Readynas Surveillance31/8/201617/6/2026
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.
ModificadaAlta (7.5)12%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
ModificadaAlta (7.5)54%💥 ExploitNetgear Readynas SurveillanceNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
ModificadaCrítica (9.8)71%💥 ExploitNetgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
ModificadaCrítica (9.8)95%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
ModificadaMedia (6.5)1.6%—Limesurvey28/6/201517/6/2026
SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.
ModificadaMedia (6.5)1.6%—Limesurvey18/6/201517/6/2026
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
ModificadaAlta (7.5)4.7%💥 ExploitSympies Wordpress Survey AND Poll26/2/201517/6/2026
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.
ModificadaMedia (6.5)1.7%💥 ExploitClassapps Selectsurvey.net6/11/201417/6/2026
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to execute arbitrary SQL commands via the SurveyID parameter to…
ModificadaMedia (5.4)0.27%—Harvestyourdata Droid Survey Offline Forms20/10/201417/6/2026
The droid Survey Offline Forms (aka com.contact.droidSURVEY) application 2.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Survey.com Mobile22/9/201417/6/2026
The Survey.com Mobile (aka com.survey.android) application 3.2.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.5%—Limesurvey21/7/201417/6/2026
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.
ModificadaAlta (7.5)1.9%—Limesurvey21/7/201417/6/2026
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.
ModificadaMedia (4.3)1.5%—Limesurvey21/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to…
ModificadaMedia (4.3)2.2%—Cisco Video Surveillance Indoor Fixed Dome IP HD Camera25/1/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.
ModificadaMedia (6.8)1.6%—Cisco Video Surveillance Operations Manager24/1/201417/6/2026
Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID…
ModificadaMedia (6.4)1.2%—Cisco Video Surveillance 4000 IP CameraCisco Video Surveillance 4300e IP CameraCisco Video Surveillance 4500e IP Camera16/10/201316/6/2026
The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.
ModificadaMedia (5)1.3%—Cisco Video Surveillance Operations Manager30/9/201316/6/2026
The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.
ModificadaAlta (10)8.5%—HP Identity Driven ManagerHP Procurve Manager16/9/201316/6/2026
The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745.
Orbitaley — Vulnerabilidades