Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 47% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Crítica (9.1) | 50% | — | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+11 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information.… | |
| Analizada | Alta (7.5) | 78% | 💥 PoC | Netapp Oncommand InsightApache ActivemqApache JmeterXstream+9 | 22/3/2021 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by… | |
| Modificada | Media (5.9) | 0.85% | — | Tweetstream Project Tweetstream | 19/2/2021 | 17/6/2026 | TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack. | |
| Modificada | Media (5.9) | 0.88% | — | Twitter-stream Project Twitter-stream | 19/2/2021 | 17/6/2026 | In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused). | |
| Modificada | Media (5.5) | 0.33% | — | Nfstream | 16/2/2021 | 17/6/2026 | An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is created, it will cause a memory leak that may result in a local denial of service (DoS). | |
| Modificada | Media (5.4) | 0.85% | — | IBM Automation Workstream ServicesIBM Business Process ManagerIBM Business Automation Workflow | 21/12/2020 | 17/6/2026 | IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445. | |
| Modificada | Alta (7.5) | 1.3% | — | Emerson X-stream Enhanced Xegp FirmwareEmerson X-stream Enhanced Xegk FirmwareEmerson X-stream Enhanced Xefd FirmwareEmerson X-stream Enhanced Xexf Firmware | 21/12/2020 | 17/6/2026 | Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information. | |
| Modificada | Crítica (9.8) | 2.1% | — | Appbase Streams | 16/12/2020 | 17/6/2026 | The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password. | |
| Analizada | Media (6.8) | 82% | 💥 PoC | Apache StrutsXstreamDebian LinuxFedoraproject Fedora | 16/12/2020 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has… | |
| Analizada | Alta (7.7) | 82% | 💥 Exploit | Apache StrutsXstreamDebian LinuxFedoraproject Fedora | 16/12/2020 | 7/10/2026 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by… | |
| Analizada | Alta (8.8) | 85% | 💥 Exploit | XstreamDebian LinuxNetapp SnapmanagerApache Activemq+11 | 16/11/2020 | 7/10/2026 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The… | |
| Modificada | Alta (7.8) | 0.29% | — | Intel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i7inh Firmware+19 | 12/11/2020 | 17/6/2026 | Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.32% | — | Intel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i7inh Firmware+19 | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel NUC 8 Mainstream-g KIT Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g KIT Nuc8i7inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i5inh FirmwareIntel NUC 8 Mainstream-g Mini PC Nuc8i7inh Firmware+19 | 12/11/2020 | 17/6/2026 | Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.6) | 2.1% | — | Leostream Connection Broker | 6/10/2020 | 17/6/2026 | Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the admin to upload a malicious Perl script that… | |
| Analizada | Alta (7.5) | 1.5% | — | Telestream MediusTelestream Sentry | 22/9/2020 | 17/6/2026 | Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a page=login request to index.php (aka the server login page). | |
| Modificada | Alta (8.8) | 1.3% | — | IBM Event Streams | 14/8/2020 | 17/6/2026 | IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233. | |
| Modificada | Alta (7.8) | 0.31% | — | Ricoh Streamline NX Client ToolRicoh Streamline NX PC Client | 4/8/2020 | 17/6/2026 | An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges. | |
| Modificada | Alta (7.8) | 0.37% | — | Wowza Streaming Engine | 3/8/2020 | 17/6/2026 | Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza… | |
| Modificada | Media (5.4) | 0.81% | — | Wowza Streaming Engine | 3/8/2020 | 17/6/2026 | Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5. | |
| Modificada | Alta (7.8) | 1.4% | — | Toyota Global Techstream | 30/7/2020 | 17/6/2026 | Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.7% | — | Grandstream Ht801 FirmwareGrandstream Ht802 FirmwareGrandstream Ht812 FirmwareGrandstream Ht814 Firmware+2 | 29/7/2020 | 17/6/2026 | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt. | |
| Modificada | Alta (7.5) | 3.4% | — | Grandstream Ht801 FirmwareGrandstream Ht802 FirmwareGrandstream Ht812 FirmwareGrandstream Ht814 Firmware+2 | 29/7/2020 | 17/6/2026 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication… | |
| Modificada | Alta (7.5) | 4.1% | — | Grandstream Ht801 FirmwareGrandstream Ht802 FirmwareGrandstream Ht812 FirmwareGrandstream Ht814 Firmware+2 | 29/7/2020 | 17/6/2026 | Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service. |