Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.3% | — | Linuxfoundation Nats-serverNats Streaming Server | 10/3/2022 | 17/6/2026 | NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected. | |
| Modificada | Crítica (9.8) | 1.3% | — | Excel Streaming Reader Project Excel Streaming Reader | 2/3/2022 | 17/6/2026 | Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround. | |
| Modificada | Media (6.1) | 0.20% | — | Gnome-shellCentos Stream | 18/2/2022 | 17/6/2026 | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked… | |
| Modificada | Alta (7.8) | 0.30% | — | Splashtop Streamer | 15/2/2022 | 17/6/2026 | Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | |
| Modificada | Alta (8.8) | 1.3% | — | Linuxfoundation Nats-serverNats Streaming Server | 8/2/2022 | 17/6/2026 | NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature. | |
| Modificada | Alta (7.5) | 1.2% | — | High Resolution Streaming Image Server Project High Resolution Streaming Image Server | 7/2/2022 | 17/6/2026 | IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters. | |
| Modificada | Alta (7.5) | 7.9% | — | JenkinsXstreamFedoraproject FedoraDebian Linux+7 | 1/2/2022 | 17/6/2026 | XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input… | |
| Modificada | Media (4.9) | 1.3% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link. | |
| Modificada | Alta (7.2) | 0.96% | — | Leostream Connection Broker | 18/1/2022 | 17/6/2026 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell EMC Streaming Data Platform | 30/11/2021 | 17/6/2026 | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user. | |
| Modificada | Media (6.5) | 0.70% | — | Dell EMC Streaming Data Platform | 30/11/2021 | 17/6/2026 | Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information. | |
| Modificada | Alta (8.8) | 0.87% | — | Dell EMC Streaming Data Platform | 30/11/2021 | 17/6/2026 | Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database. | |
| Modificada | Media (5.3) | 1.0% | — | Dell EMC Streaming Data Platform | 30/11/2021 | 17/6/2026 | Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of the attacker's choice. | |
| Modificada | Media (6.5) | 1.2% | — | Dell EMC Streaming Data Platform | 30/11/2021 | 17/6/2026 | Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format. | |
| Modificada | Media (5.5) | 0.22% | — | Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4w FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+99 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.8) | 1.6% | — | XWP Stream | 17/11/2021 | 17/6/2026 | The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue. | |
| Modificada | Alta (8.8) | 2.0% | — | Grandstream Ht801 Firmware | 28/10/2021 | 17/6/2026 | An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host. | |
| Modificada | Alta (8.8) | 7.4% | 💥 PoC | Grandstream Ht801 Firmware | 28/10/2021 | 17/6/2026 | Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device.… | |
| Modificada | Alta (7.2) | 1.3% | — | Qnap Media Streaming Add-on | 22/10/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming add-on: QTS 5.0.0: Media Streaming add-on… | |
| Modificada | Media (5.4) | 0.58% | — | Bplugins Streamcast Radio Player | 18/10/2021 | 17/6/2026 | The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Crítica (9.8) | 1.7% | — | Vitec Exterity AvediaserverVitec Exterity Avediastream Encoders FirmwareVitec Avediastream M9605 FirmwareVitec Avediastream M9400 Firmware+6 | 8/10/2021 | 17/6/2026 | VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. | |
| Modificada | Media (6.5) | 3.3% | 💥 PoC | Wowza Streaming Engine | 5/10/2021 | 17/6/2026 | Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through… | |
| Modificada | Alta (8.1) | 0.88% | — | Wowza Streaming Engine | 5/10/2021 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza… | |
| Modificada | Alta (8.8) | 0.71% | — | Streama Project Streama | 29/9/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send… |