Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)77%💥 ExploitXstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1328/5/20217/10/2026
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's…
ModificadaMedia (6.1)0.70%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.
ModificadaMedia (6.1)0.64%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.
ModificadaMedia (5.3)0.90%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.
ModificadaAlta (7.5)1.4%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.
ModificadaCrítica (9.8)1.8%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.
ModificadaAlta (7.5)0.45%—Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware20/5/202117/6/2026
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
ModificadaAlta (7.5)1.2%—Veritystream Msow Solutions6/5/202117/6/2026
Primary Source Verification in VerityStream MSOW Solutions before 3.1.1 allows an anonymous internet user to discover Social Security Number (SSN) values via a brute-force attack on a (sometimes hidden) search field, because the last four SSN digits are part of the supported combination of search selectors. This…
ModificadaAlta (7.5)1.1%—Live555 Streaming Media29/4/202117/6/2026
Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16.
ModificadaAlta (7.1)0.39%—Wowza Streaming Engine23/4/202117/6/2026
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration.
ModificadaMedia (5.5)0.30%—Wowza Streaming Engine23/4/202117/6/2026
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
ModificadaAlta (7.8)1.8%—GstreamerDebian LinuxRedhat Enterprise Linux19/4/202117/6/2026
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
ModificadaAlta (7.8)1.2%—GstreamerDebian LinuxRedhat Enterprise Linux19/4/202117/6/2026
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
ModificadaCrítica (9.8)1.8%—Qnap QTSQnap Media Streaming Add-onQnap Multimedia Console17/4/202117/6/2026
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the…
ModificadaCrítica (9.8)1.8%—Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+329/3/202117/6/2026
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
ModificadaAlta (7.2)2.4%—Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+329/3/202117/6/2026
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
ModificadaAlta (7.8)0.35%—Bosch Video Streaming Gateway25/3/202117/6/2026
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same…
AnalizadaCrítica (9.1)82%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to…
AnalizadaCrítica (9.8)15%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaAlta (8.6)47%💥 PoCNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1322/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed…
AnalizadaAlta (7.5)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security…
AnalizadaCrítica (9.8)14%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…
AnalizadaCrítica (9.9)72%💥 ExploitNetapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the…
AnalizadaCrítica (9.8)76%—Netapp Oncommand InsightApache ActivemqApache JmeterXstream+1222/3/20217/10/2026
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation…