Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 1.3% | — | Apereo Opencast | 30/1/2020 | 17/6/2026 | In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me… | |
| Modificada | Alta (7.5) | 1.2% | — | Apereo Opencast | 30/1/2020 | 17/6/2026 | Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to… | |
| Modificada | Alta (8.8) | 0.94% | — | Apereo Opencast | 30/1/2020 | 17/6/2026 | Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the same credentials without ever needing… | |
| Modificada | Alta (8.1) | 0.63% | — | Apereo Opencast | 30/1/2020 | 17/6/2026 | Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same username and password to collide which is problematic especially for popular users… | |
| Modificada | Alta (7.5) | 0.98% | — | Apereo Opencast | 30/1/2020 | 17/6/2026 | Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly handing out public access to events without… | |
| Modificada | Media (6.5) | 0.76% | — | Apereo Opencast | 17/11/2017 | 17/6/2026 | In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have… | |
| Modificada | Alta (8.8) | 1.9% | — | Opencast | 17/11/2017 | 17/6/2026 | Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ramoncastro Siestta | 4/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Ramoncastro Siestta | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack. | |
| Modificada | Media (6.5) | 3.2% | 💥 Exploit | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI. | |
| Modificada | Media (5) | 1.5% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication attempt, which includes sensitive memory in the response. NOTE: this is referred to as a "memory leak" by some sources, but… | |
| Modificada | Media (4) | 1.1% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Streamaudio Chaincast Proxymanager Activex Control | 12/1/2008 | 16/6/2026 | Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Ncaster | 14/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter. |