Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 77% | 💥 Exploit | XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+13 | 28/5/2021 | 7/10/2026 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's… | |
| Modificada | Media (6.1) | 0.70% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information. | |
| Modificada | Media (6.1) | 0.64% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data. | |
| Modificada | Media (5.3) | 0.90% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs. | |
| Modificada | Crítica (9.8) | 1.8% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.45% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 20/5/2021 | 17/6/2026 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access. | |
| Modificada | Alta (7.5) | 1.2% | — | Veritystream Msow Solutions | 6/5/2021 | 17/6/2026 | Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a (sometimes hidden) search field, because the last four SSN digits are part of the supported combination of search selectors. This… | |
| Modificada | Alta (7.5) | 1.1% | — | Live555 Streaming Media | 29/4/2021 | 17/6/2026 | Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16. | |
| Modificada | Alta (7.1) | 0.39% | — | Wowza Streaming Engine | 23/4/2021 | 17/6/2026 | Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration. | |
| Modificada | Media (5.5) | 0.30% | — | Wowza Streaming Engine | 23/4/2021 | 17/6/2026 | Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords. | |
| Modificada | Alta (7.8) | 1.8% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. | |
| Modificada | Alta (7.8) | 1.2% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files. | |
| Modificada | Crítica (9.8) | 1.8% | — | Qnap QTSQnap Media Streaming Add-onQnap Multimedia Console | 17/4/2021 | 17/6/2026 | An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+3 | 29/3/2021 | 17/6/2026 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. | |
| Modificada | Alta (7.2) | 2.4% | — | Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+3 | 29/3/2021 | 17/6/2026 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. | |
| Modificada | Alta (7.8) | 0.35% | — | Bosch Video Streaming Gateway | 25/3/2021 | 17/6/2026 | Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same… | |
| Analizada | Crítica (9.1) | 82% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to… | |
| Analizada | Crítica (9.8) | 15% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Alta (8.6) | 47% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+13 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed… | |
| Analizada | Alta (7.5) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security… | |
| Analizada | Crítica (9.8) | 14% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… | |
| Analizada | Crítica (9.9) | 72% | 💥 Exploit | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the… | |
| Analizada | Crítica (9.8) | 76% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+12 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation… |