Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)4.8%—Opensuse LeapOpensuseBouncycastle Bouncy Castle Crypto PackageOracle Application Testing Suite+39/11/201517/6/2026
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
ModificadaMedia (5)4.3%—Xiph IcecastDebian LinuxOpensuse29/4/201517/6/2026
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
ModificadaAlta (10)4.2%—Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+127/1/201517/6/2026
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
ModificadaAlta (7.8)2.0%—Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+127/1/201517/6/2026
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
ModificadaMedia (4.6)0.49%—Icecast10/12/201417/6/2026
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
ModificadaMedia (5)3.0%—Icecast3/12/201417/6/2026
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.
ModificadaMedia (5.4)0.27%—Afsinc Metalcasting Newsstand4/10/201417/6/2026
The Metalcasting Newsstand (aka air.com.yudu.ReaderAIR3017071) application 3.12.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Wordbox Mahabharata Audiocast23/9/201417/6/2026
The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Friendcasterapp Friendcaster23/9/201417/6/2026
The Friendcaster (aka uk.co.senab.blueNotifyFree) application 5.4.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Onelouder Friendcaster Chat9/9/201417/6/2026
The FriendCaster Chat (aka com.handmark.friendcaster.chat) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Comcast Xfinity Constant Guard Mobile9/9/201417/6/2026
The XFINITY Constant Guard Mobile (aka com.whitesky.mobile.android) application 3.1.140603 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)3.2%💥 ExploitShoutcast Dnas16/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field.
ModificadaMedia (4.3)7.9%💥 ExploitCastor Project CastorOpensuseOpensuse Project Opensuse11/6/201417/6/2026
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
ModificadaAlta (7.5)3.8%💥 ExploitMini-stream Castripper3/1/201416/6/2026
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667.
ModificadaMedia (5.4)0.57%—IBM Webshere Cast Iron Cloud Integration22/2/201316/6/2026
Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
ModificadaMedia (4)3.0%—Bouncycastle Bc-javaBouncycastle Legion-of-the-bouncy-castle-c#-cryptography-api8/2/201316/6/2026
The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and…
ModificadaMedia (5)2.2%—Xiph Icecast20/11/201216/6/2026
icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.
ModificadaAlta (9.3)32%💥 ExploitCastillobueno Ccmplayer15/9/201216/6/2026
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.
ModificadaAlta (7.2)1.1%💥 ExploitSopcast30/12/201116/6/2026
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program.
ModificadaAlta (7.5)1.2%💥 ExploitPreproject PRE Podcast Portal9/10/201116/6/2026
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaMedia (5)1.2%—Betella Podcast Generator24/9/201116/6/2026
Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files.
ModificadaMedia (5)2.1%—Inventivetec Mediacast10/5/201116/6/2026
MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote attackers to obtain sensitive information via unspecified vectors related to the Public/ directory tree.
ModificadaAlta (7.5)1.8%—Inventivetec Mediacast10/5/201116/6/2026
Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm.
ModificadaAlta (7.5)1.5%—Inventivetec Mediacast10/5/201116/6/2026
MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to an "XML injection" issue.
ModificadaMedia (4.3)0.89%—Inventivetec Mediacast10/5/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.