Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Baja (3.8) | 0.21% | — | Vmware Spring Cloud Stream | 27/8/2026 | 4/9/2026 | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | |
| Analizada | Alta (7.8) | 0.21% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The… | |
| Analizada | Alta (7.8) | 0.22% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.24% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.23% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.21% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Aplazada | Alta (8.3) | 0.41% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs… | |
| Aplazada | Alta (8.8) | 0.20% | — | StreambertAIElectronAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler… | |
| Aplazada | Alta (8.4) | 0.16% | — | StreambertAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and… | |
| Aplazada | Media (6.9) | 0.36% | — | StreambertAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Security-Policy header… | |
| Aplazada | Alta (8.8) | 0.18% | — | StreambertAI | 18/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle url using the file: URI scheme and passes its decoded pathname to… | |
| Aplazada | Media (5.3) | 0.30% | — | StreamaAI | 13/8/2026 | 24/9/2026 | streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching… | |
| En análisis | Media (6.1) | 0.15% | — | GstreamerRedhat Enterprise Linux | 12/8/2026 | 23/9/2026 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This… | |
| En análisis | Media (6.6) | 0.15% | — | GstreamerRedhat Enterprise Linux | 12/8/2026 | 23/9/2026 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the… | |
| Aplazada | Crítica (10) | 0.55% | — | StreambertAI | 11/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0… | |
| Aplazada | Crítica (9.3) | 0.36% | — | StreambertAI | 11/8/2026 | 9/9/2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution.… | |
| Pendiente de análisis | Alta (7.1) | 0.58% | — | Gstreamer Gst-plugins-uglyAI | 10/8/2026 | 16/9/2026 | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads.… | |
| Pendiente de análisis | Alta (7.6) | 0.38% | — | Gstreamer Gst-plugins-badAI | 10/8/2026 | 18/9/2026 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to… | |
| Aplazada | Baja (1.9) | 0.17% | — | Incomestreamsurfer ROO Code Memory Bank MCP ServerAI | 9/8/2026 | 14/8/2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation… | |
| Aplazada | Media (6.5) | 0.38% | — | StreamAI | 7/8/2026 | 12/8/2026 | The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all… | |
| Pendiente de análisis | Alta (7.5) | 0.96% | — | Gstreamer Gst-plugins-goodAI | 6/8/2026 | 23/9/2026 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever… | |
| Pendiente de análisis | Alta (7.8) | 0.34% | — | GstreamerAI | 29/7/2026 | 30/7/2026 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Aplazada | Alta (7.1) | 0.24% | — | Streamsoft Business IntelligenceAI | 29/7/2026 | 30/7/2026 | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login. | |
| Aplazada | Crítica (9.8) | 0.96% | — | StreamitAI | 29/7/2026 | 30/7/2026 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create… |