Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.26% | — | Raimersoft Tapinradio | 7/2/2026 | 17/6/2026 | TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality. | |
| Analizada | Media (6.7) | 0.26% | — | Raimersoft Tapinradio | 7/2/2026 | 17/6/2026 | TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address field with 3000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality. | |
| Analizada | Media (6.7) | 0.50% | — | Raimersoft Tapinradio | 27/1/2026 | 17/6/2026 | TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflowing input fields. Attackers can paste a large buffer of 20,000 characters into the username and address fields to cause the application to become unresponsive and require… | |
| Aplazada | Media (5.4) | 0.19% | — | Softlabbd Radio PlayerAI | 23/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.91. | |
| Aplazada | Alta (7.1) | 0.22% | — | Qantumthemes KentharadioAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes KenthaRadio qt-kentharadio allows Reflected XSS.This issue affects KenthaRadio: from n/a through <= 2.2.0. | |
| Aplazada | Media (4.6) | 0.41% | — | Raimersoft RarmaradioAI | 16/1/2026 | 17/6/2026 | RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger application instability… | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes Rare RadioAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Rare Radio rareradio allows PHP Local File Inclusion.This issue affects Rare Radio: from n/a through <= 1.0.15.1. | |
| Aplazada | Alta (8.7) | 0.43% | — | R Radio Network FM TransmitterAI | 4/12/2025 | 26/9/2026 | R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access. | |
| Analizada | Alta (7.5) | 0.41% | — | Elcaradio Star150 FirmwareElcaradio Bp1000 FirmwareElcaradio Star300 FirmwareElcaradio Star2000 Firmware+2 | 19/11/2025 | 17/6/2026 | The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models, contains an information disclosure vulnerability allowing unauthenticated attackers to retrieve admin credentials and system settings via an unprotected /setup.xml endpoint. The… | |
| Analizada | Media (6.1) | 0.22% | — | Radioinorr SVX Portal | 14/11/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php. | |
| Analizada | Media (6) | 0.27% | — | Radioinorr SVX Portal | 14/11/2025 | 17/6/2026 | SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php. | |
| Analizada | Crítica (10) | 0.74% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally,… | |
| Analizada | Crítica (10) | 0.77% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and… | |
| Analizada | Crítica (10) | 0.66% | — | Radiometrics Vizair | 4/11/2025 | 17/6/2026 | Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially… | |
| Aplazada | Media (6.1) | 0.28% | — | Radioinorr SVX PortalAI | 9/10/2025 | 17/6/2026 | Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arbitrary code via the TG parameter on last_heard_page.php component | |
| Aplazada | Alta (7.1) | 0.24% | — | Lambertgroup Html5 Radio Player - Wpbakery Page Builder AddonAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg_radio_player_addon_visual_composer allows Reflected XSS.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5. | |
| Aplazada | Alta (7.1) | 0.23% | — | Lambertgroup Radio Player Shoutcast AND IcecastAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Radio Player Shoutcast & Icecast lbg-audio4-html5-shoutcast allows Reflected XSS.This issue affects Radio Player Shoutcast & Icecast: from n/a through <= 4.4.7. | |
| Aplazada | Alta (7.1) | 0.24% | — | Lambertgroup Shout Html5 Radio Player With ADSAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support lbg-audio8-html5-radio-ads allows Reflected XSS.This issue affects SHOUT - HTML5 Radio Player With Ads - ShoutCast and IceCast Support:… | |
| Aplazada | Alta (7.5) | 0.52% | — | Lambertgroup Html5 Radio Player - Wpbakery Page Builder AddonAI | 16/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon lbg-cleverbakery allows Path Traversal.This issue affects HTML5 Radio Player - WPBakery Page Builder Addon: from n/a through <= 2.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Netmix Radio StationAI | 4/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station allows Cross Site Request Forgery.This issue affects Radio Station: from n/a through <= 2.5.12. | |
| Aplazada | Alta (7.1) | 0.28% | — | Lambertgroup Sticky Radio PlayerAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcast_sticky allows Reflected XSS.This issue affects Sticky Radio Player: from n/a through <= 3.4. | |
| Analizada | Alta (7.5) | 0.66% | — | Gradio Project Gradio | 30/5/2025 | 17/6/2026 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any readable file from… | |
| Aplazada | Media (6.3) | 0.26% | — | Gradio-app GradioAI | 29/5/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to erweiterte Rechte. It is possible to initiate the attack remotely. The complexity of an attack… | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Radio Player Shoutcast IcecastAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin audio4-html5 allows Blind SQL Injection.This issue affects Radio Player Shoutcast & Icecast WordPress Plugin: from n/a through <= 4.4.6. | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Sticky Radio PlayerAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcast_sticky allows SQL Injection.This issue affects Sticky Radio Player: from n/a through <= 3.4. |