Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.69% | — | Voter-js Project Voter-js | 6/1/2023 | 17/6/2026 | A vulnerability was found in ScottTZhang voter-js and classified as critical. Affected by this issue is some unknown functionality of the file main.js. The manipulation leads to sql injection. The patch is identified as 6317c67a56061aeeaeed3cf9ec665fd9983d8044. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Media (6.5) | 0.88% | — | Scytl Secure Vote | 27/2/2021 | 17/6/2026 | An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, an attacker can inject wrong IP addresses into these logs. | |
| Modificada | Crítica (9.8) | 2.5% | — | Scytl Secure Vote | 27/2/2021 | 17/6/2026 | An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation. | |
| Modificada | Alta (7.5) | 1.2% | — | Scytl Secure Vote | 27/2/2021 | 17/6/2026 | An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A different password cannot be set because of the implementation in code. | |
| Modificada | Alta (7.5) | 1.3% | — | Scytl Secure Vote | 27/2/2021 | 17/6/2026 | An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST request to the /sdm-ws-rest/preconfiguration URI. | |
| Modificada | Crítica (9.8) | 3.1% | — | Calendar01 Project Calendar01Calendar02 Project Calendar02Calendarform01 Project Calendarform01Gallery01 Project Gallery01+4 | 4/8/2020 | 17/6/2026 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0,… | |
| Modificada | Alta (8.8) | 2.7% | — | Vivotek Cc9381-hv FirmwareVivotek Fd9360-h FirmwareVivotek Fd9368-htv FirmwareVivotek Fd9380-h Firmware+196 | 28/5/2020 | 17/6/2026 | VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices. | |
| Modificada | Media (6.5) | 1.2% | — | Vivotek Cc9381-hv FirmwareVivotek Fd9360-h FirmwareVivotek Fd9368-htv FirmwareVivotek Fd9380-h Firmware+190 | 28/5/2020 | 17/6/2026 | testserver.cgi of the web service on VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to obtain arbitrary files from a camera's local filesystem. For example, this affects IT9388-HT devices. | |
| Modificada | Media (5.2) | 0.51% | — | Halvotec Raquest | 16/3/2020 | 17/6/2026 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in… | |
| Modificada | Media (5.4) | 0.74% | — | Halvotec Raquest | 16/3/2020 | 17/6/2026 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0. | |
| Modificada | Media (5.4) | 0.87% | — | Halvotec Raquest | 16/3/2020 | 17/6/2026 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Halvotec Raquest | 13/3/2020 | 17/6/2026 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to access the list of connected users as well as the session cookie for each user. Fixed in Release 10.24.11206.1 | |
| Modificada | Alta (7.5) | 1.2% | — | Halvotec Raquest | 9/3/2020 | 17/6/2026 | An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1. | |
| Modificada | Alta (8.8) | 20% | 💥 Exploit | Vivotek Pt7135 Firmware | 24/1/2020 | 16/6/2026 | A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code. | |
| Modificada | Media (6.5) | 14% | 💥 Exploit | Vivotek Pt7135 Firmware | 24/1/2020 | 16/6/2026 | A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials. | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | Vivotek Pt7135 Firmware | 24/1/2020 | 16/6/2026 | An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554. | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | Vivotek Pt7135 Firmware | 24/1/2020 | 16/6/2026 | A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | Vivotek Pt7135 Firmware | 24/1/2020 | 16/6/2026 | An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Vivotek Ip7160 FirmwareVivotek Ip7361 FirmwareVivotek Ip8332 Firmware | 27/12/2019 | 16/6/2026 | Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream | |
| Modificada | Alta (7.5) | 1.9% | — | Vivotek Camera | 18/9/2019 | 17/6/2026 | VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header. | |
| Modificada | Crítica (9.8) | 1.3% | — | Vivotek Camera | 10/9/2019 | 17/6/2026 | An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found. | |
| Modificada | Crítica (9.8) | 2.6% | — | Vivotek Camera | 10/9/2019 | 17/6/2026 | VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header. | |
| Modificada | Crítica (9.8) | 4.1% | — | Vivotek Fd8136 Firmware | 10/7/2019 | 17/6/2026 | Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other… | |
| Modificada | Crítica (9.8) | 4.4% | — | Vivotek Fd8136 Firmware | 10/7/2019 | 17/6/2026 | Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance | |
| Modificada | Crítica (9.8) | 3.2% | — | Vivotek Fd8136 Firmware | 10/7/2019 | 17/6/2026 | Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware |