Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Television | 7/8/2017 | 17/6/2026 | A vulnerability in the cache server within Cisco Videoscape Distribution Suite (VDS) for Television 3.2(5)ES1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted appliance. The vulnerability is due to excessive mapped connections exhausting the allotted resources… | |
| Modificada | Media (6.1) | 0.85% | — | Cisco Videoscape Distribution Suite Service Manager | 5/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. | |
| Modificada | Media (6.5) | 0.59% | — | Cisco Videoscape Session Resource Manager | 28/7/2016 | 17/6/2026 | Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Internet Streaming | 1/3/2016 | 17/6/2026 | The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN… | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Videoscape Distribution Suite Service Manager | 12/12/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025. | |
| Modificada | Media (5) | 1.8% | — | Cisco Videoscape Distribution Suite Service Manager | 14/11/2015 | 17/6/2026 | Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960. | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Videoscape Policy Resource Manager | 21/7/2015 | 17/6/2026 | Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Videoscape Distribution Suite Service BrokerCisco Videoscape Distribution Suite FOR Internet Streaming | 16/7/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a denial of service (device reload) via a crafted HTTP… | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Videoscape ConductorCisco Headend Digital Broadband Delivery SystemCisco Headend System Release | 30/5/2015 | 17/6/2026 | Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408. | |
| Modificada | Media (5) | 1.5% | — | Cisco Videoscape Delivery System FOR Internet Streamer | 20/3/2015 | 17/6/2026 | The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911. | |
| Modificada | Media (4.6) | 7.1% | — | Corel FastflickCorel Videostudio PRO | 15/1/2015 | 17/6/2026 | Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse u32ZLib.dll file that is located in the same folder as the file being processed. | |
| Modificada | Media (5.4) | 0.27% | — | Basketball News & Videos Project Basketball News & Videos | 20/10/2014 | 17/6/2026 | The basketball news & videos (aka com.basketbal.news.caesar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Appsgeyser Btd5 Videos | 19/10/2014 | 17/6/2026 | The BTD5 Videos (aka com.wxTYILIEIRBTD5Videos) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Allqoranvideos Koran - Alqoranvideos | 28/9/2014 | 17/6/2026 | The Koran - AlqoranVideos (aka com.alqoran.videos.example) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Vevo-watch HD Music Videos | 9/9/2014 | 17/6/2026 | The Vevo - Watch HD Music Videos (aka com.vevo) application 2.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | 9gag - Funny Pics AND Videos | 9/9/2014 | 17/6/2026 | The 9GAG - Funny pics and videos (aka com.ninegag.android.app) application 2.4.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | NQ Vault-hide SMS Pics & Videos | 9/9/2014 | 17/6/2026 | The Vault-Hide SMS, Pics & Videos (aka com.netqin.ps) application 5.0.14.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Videos Tube Project Videos Tube | 4/6/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php. | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Verytools Videospirit LiteVerytools Videospirit PRO | 20/1/2011 | 16/6/2026 | Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "value" attribute, as demonstrated using a valitem… | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Verytools Videospirit LiteVerytools Videospirit PRO | 20/1/2011 | 16/6/2026 | Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "name" attribute. NOTE: the provenance of… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Payperviewvideosoftware PAY PER Minute Video Chat Script | 9/6/2010 | 16/6/2026 | SQL injection vulnerability in index_ie.php in Pay Per Minute Video Chat Script 2.0 and 2.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Payperviewvideosoftware PAY PER Minute Video Chat Script | 9/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pay Per Minute Video Chat Script 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/memberviewdetails.php and the (2) model parameter to videos.php. | |
| Modificada | Media (4.3) | 0.91% | — | Videosearchscript PRO | 23/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 28% | 💥 Exploit | Joomlaworks JW Allvideos | 23/2/2010 | 16/6/2026 | Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter. |