Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 4.0% | — | Vitec Flamingo | 13/7/2026 | 14/8/2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the… | |
| Analizada | Crítica (9.3) | 3.3% | — | Vitec Flamingo | 13/7/2026 | 14/8/2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST… | |
| Aplazada | Media (6.5) | 0.44% | — | Goadmingroup GoadminAI | 1/7/2026 | 2/7/2026 | SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints | |
| Aplazada | Media (5.3) | 0.27% | — | Hsiaoming JoserfcAI | 17/6/2026 | 23/6/2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion. The normal JWS… | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+136 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon 480 5G Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 3 Mobile Platform Firmware+261 | 1/6/2026 | 22/7/2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | |
| Aplazada | Media (5.5) | 0.33% | — | Sourcecodester PET Grooming Management SoftwareAI | 1/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.41% | — | Changmingxie Tcc-transactionAIAlibaba FastjsonAI | 25/5/2026 | 23/7/2026 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester PET Grooming Management SoftwareAI | 30/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (8.8) | 0.95% | — | Niteothemes CMP Coming Soon MaintenanceAI | 18/4/2026 | 17/6/2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability… | |
| Analizada | Crítica (9.9) | 0.37% | — | Sonicverse Radio Audio Streaming Stack | 9/4/2026 | 17/6/2026 | Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner… | |
| Aplazada | Media (5.5) | 0.26% | — | Seedprod Coming Soon PageAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Server Side Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8. | |
| Aplazada | Alta (7.5) | 0.16% | — | Analytify Under Construction Coming Soon AND Maintenance ModeAI | 7/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1. | |
| Aplazada | Baja (2.1) | 0.32% | — | Mingsoft McmsAI | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.47% | — | Mingsoft McmsAI | 27/3/2026 | 17/6/2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Media (6.9) | 0.14% | — | Anming MP3 CD BurnerAI | 22/3/2026 | 17/6/2026 | AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string. Attackers can paste a 6000-byte payload into the registration name field to trigger a denial of service condition. | |
| Analizada | Baja (2.7) | 0.32% | — | Qnap Media Streaming Add-on | 20/3/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Media Streaming Add-on 500.1.1 and later | |
| Analizada | Media (5.1) | 0.24% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost,… | |
| Analizada | Media (6.9) | 0.16% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin… | |
| Analizada | Alta (8.7) | 0.21% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true'… | |
| Analizada | Alta (8.5) | 0.21% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine… | |
| Analizada | Baja (2.1) | 0.40% | — | Mayurik PET Grooming Management Software | 8/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the component Financial Report Page. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |