Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections only from 127.0.0.1, which makes it easier for remote attackers to have an unspecified impact via a TCP session. | |
| Modificada | Media (5) | 1.0% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by reading an unspecified password data store, a different vulnerability than CVE-2010-0216. | |
| Modificada | Media (5) | 1.6% | — | Inventivetec Mediacast | 10/5/2011 | 16/6/2026 | authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter. | |
| Modificada | Media (6.9) | 0.40% | — | Pedro Castro Gnome-subtitles | 20/10/2010 | 16/6/2026 | gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Iscripts Visualcaster | 25/7/2010 | 16/6/2026 | SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ramoncastro Siestta | 4/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Ramoncastro Siestta | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack. | |
| Modificada | Media (6.5) | 3.2% | 💥 Exploit | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI. | |
| Modificada | Media (5) | 1.5% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication attempt, which includes sensitive memory in the response. NOTE: this is referred to as a "memory leak" by some sources, but… | |
| Modificada | Media (4) | 1.1% | — | Geopp Geo++ Gncaster | 4/2/2010 | 16/6/2026 | admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Videosbroadcastyourself Videos Broadcast Yourself | 21/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Xigla Absolute Podcast.net | 14/7/2009 | 16/6/2026 | Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Castro XL Torrentvolve | 17/6/2009 | 16/6/2026 | Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter. | |
| Modificada | Alta (9.3) | 21% | 💥 Exploit | Mini-stream Castripper | 18/5/2009 | 16/6/2026 | Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long entry in a .m3u file, a different vector than CVE-2009-5137. | |
| Modificada | Media (6.5) | 1.8% | 💥 Exploit | Podcast Generator | 2/4/2009 | 16/6/2026 | Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Podcast Generator | 2/4/2009 | 16/6/2026 | core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter. | |
| Modificada | Alta (10) | 2.4% | — | Bouncycastle Bc-javaBouncycastle Bouncy-castle-crypto-package | 30/3/2009 | 16/6/2026 | The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes." | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | Sopcast Sopcore Activex Control | 4/3/2009 | 16/6/2026 | Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Insun Podcast Feedcms | 2/3/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Getmiro Broadcast Machine | 25/2/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Preprojects PRE Podcast Portal | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.6% | — | Fujitsu Systemcastwizard Lite | 26/1/2009 | 16/6/2026 | Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors. | |
| Modificada | Alta (10) | 5.5% | — | Fujitsu Systemcastwizard Lite | 26/1/2009 | 16/6/2026 | Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet. |