Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 4.8% | — | Opensuse LeapOpensuseBouncycastle Bouncy Castle Crypto PackageOracle Application Testing Suite+3 | 9/11/2015 | 17/6/2026 | The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack." | |
| Modificada | Media (5) | 4.3% | — | Xiph IcecastDebian LinuxOpensuse | 29/4/2015 | 17/6/2026 | Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg." | |
| Modificada | Alta (10) | 4.2% | — | Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+1 | 27/1/2015 | 17/6/2026 | The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session. | |
| Modificada | Alta (7.8) | 2.0% | — | Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+1 | 27/1/2015 | 17/6/2026 | The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request. | |
| Modificada | Media (4.6) | 0.49% | — | Icecast | 10/12/2014 | 17/6/2026 | Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (5) | 3.0% | — | Icecast | 3/12/2014 | 17/6/2026 | Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors. | |
| Modificada | Media (5.4) | 0.27% | — | Afsinc Metalcasting Newsstand | 4/10/2014 | 17/6/2026 | The Metalcasting Newsstand (aka air.com.yudu.ReaderAIR3017071) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Wordbox Mahabharata Audiocast | 23/9/2014 | 17/6/2026 | The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Friendcasterapp Friendcaster | 23/9/2014 | 17/6/2026 | The Friendcaster (aka uk.co.senab.blueNotifyFree) application 5.4.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Onelouder Friendcaster Chat | 9/9/2014 | 17/6/2026 | The FriendCaster Chat (aka com.handmark.friendcaster.chat) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Comcast Xfinity Constant Guard Mobile | 9/9/2014 | 17/6/2026 | The XFINITY Constant Guard Mobile (aka com.whitesky.mobile.android) application 3.1.140603 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Shoutcast Dnas | 16/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field. | |
| Modificada | Media (4.3) | 7.9% | 💥 Exploit | Castor Project CastorOpensuseOpensuse Project Opensuse | 11/6/2014 | 17/6/2026 | The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Mini-stream Castripper | 3/1/2014 | 16/6/2026 | Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667. | |
| Modificada | Media (5.4) | 0.57% | — | IBM Webshere Cast Iron Cloud Integration | 22/2/2013 | 16/6/2026 | Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (4) | 3.0% | — | Bouncycastle Bc-javaBouncycastle Legion-of-the-bouncy-castle-c#-cryptography-api | 8/2/2013 | 16/6/2026 | The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and… | |
| Modificada | Media (5) | 2.2% | — | Xiph Icecast | 20/11/2012 | 16/6/2026 | icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Castillobueno Ccmplayer | 15/9/2012 | 16/6/2026 | Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Sopcast | 30/12/2011 | 16/6/2026 | SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Preproject PRE Podcast Portal | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (5) | 1.2% | — | Betella Podcast Generator | 24/9/2011 | 16/6/2026 | Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files. | |
| Modificada | Media (5) | 2.1% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote attackers to obtain sensitive information via unspecified vectors related to the Public/ directory tree. | |
| Modificada | Alta (7.5) | 1.8% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm. | |
| Modificada | Alta (7.5) | 1.5% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to an "XML injection" issue. | |
| Modificada | Media (4.3) | 0.89% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |