Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Madrasthemes MAS VideosAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in MadrasThemes MAS Videos masvideos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MAS Videos: from n/a through <= 1.3.2. | |
| Analizada | Baja (0.1) | 0.14% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video… | |
| Analizada | Baja (0.1) | 0.08% | — | Qnap Video Station | 11/3/2026 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following… | |
| Analizada | Media (5.5) | 0.44% | — | Wwbn Avideo | 10/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlist names, video IDs,… | |
| Analizada | Baja (2.1) | 0.50% | — | Tiandy Video Surveillance System Firmware | 9/3/2026 | 17/6/2026 | A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File.java. The manipulation of the argument fileName leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.4) | 0.19% | — | Show Youtube VideoAI | 7/3/2026 | 17/6/2026 | The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.38% | — | Videowhisper Paid Videochat Turnkey SiteAI | 7/3/2026 | 17/6/2026 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.20. This is due to videowhisper_register_form() function not restricting user roles that can be set during registration. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 6.8% | 💥 Exploit | Wwbn Avideo-encoder | 6/3/2026 | 17/6/2026 | AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration secrets, internal… | |
| Analizada | Crítica (9.8) | 0.64% | — | Wwbn Avideo | 6/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. An attacker who can reach port 11211… | |
| Analizada | Crítica (9.3) | 1.0% | — | Wwbn Avideo | 6/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. The issue allowed an authenticated administrator to upload a specially crafted ZIP archive containing executable… | |
| Analizada | Crítica (9.8) | 1.4% | — | Wwbn Avideo | 6/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is supplied via a JSON-formatted POST… | |
| Aplazada | Media (6.1) | 0.24% | — | ALL IN ONE Video GalleryAI | 4/3/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Pendiente de análisis | Crítica (9.8) | 0.50% | — | Step Video-t2vAI | 3/3/2026 | 17/6/2026 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+160 | 2/3/2026 | 17/6/2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+39 | 2/3/2026 | 17/6/2026 | Transient DOS when MAC configures config id greater than supported maximum value. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+174 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+118 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p FirmwareQualcomm Sa7775p Firmware+165 | 2/3/2026 | 17/6/2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+184 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | |
| Aplazada | Media (6.3) | 0.51% | — | Videolan VLC FOR AndroidAI | 26/2/2026 | 14/7/2026 | VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature due to missing or insufficient rate limiting on one-time password (OTP) verification. The Remote Access Server uses a 4-digit OTP and does not enforce effective throttling or lockout within the OTP… | |
| Aplazada | Baja (2.3) | 0.41% | — | Videolan VLC FOR AndroidAI | 26/2/2026 | 14/7/2026 | VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under the configured download directory without canonicalization or directory… |