Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)3.1%💥 ExploitBitscast16/5/200716/6/2026
BitsCast 0.13.0 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) mediante un ítem de un feed RSS 2.0 con ciertas cadenas inválidas en un elemento pubDate, como ha sido demostrado con patrones "../A" o "A/../" repetidos.
ModificadaMedia (6.5)1.3%—Activecampaign 1-2-all Broadcast Email11/5/200716/6/2026
Vulnerabilidad de lista negra incompleta en filemanager/browser/default/connectors/php/config.php en el módulo FCKeditor, tal y como se usa en ActiveCampaign 1-2-All (también conocido como 12All) 4.50 hasta 4.53.13, y posiblemente otros productos, permite a administradores remotos autenticados promocionar y…
ModificadaAlta (7.5)6.1%💥 ExploitMxbb MX Shotcast26/4/200716/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en el tinfo1.php del módulo Shotcast 1.0 RC2 para mxBB permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro mx_root_path.
ModificadaAlta (9.3)5.6%—Xiph Icecast Ezstream8/3/200716/6/2026
Múltiples desbordamientos de búfer en el src/ezstream.c del Ezstream before 0.3.0 permiten a atacantes remotos ejecutar código de su elección mediante la manipulación del fichero de configuración XML procesado por (1) la función urlParse, lo que provoca desbordamientos basados en pila y (2) la función ReplaceString,…
ModificadaMedia (4.3)1.8%💥 ExploitNullsoft Shoutcast Server2/3/200716/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Nullsoft ShoutcastServer 1.9.7 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante la URI top-level en el interfaz Incoming (puerto tcp/8001), que no es gestionado apropiadamente en la interfaz de administrador cuando se…
ModificadaMedia (5.1)2.6%💥 ExploitCastor PHP WEB Builder24/10/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en lib/rs.php en Castor 1.1.1 permite a atacantes remotos ejecutar código PHP de su elección mediante el parámetro rootpath.
ModificadaAlta (7.5)1.3%—Castor24/10/200616/6/2026
Múltiples vulnerabilidades de inclusión remota de archivo en Castor 1.1.1 permiten a atacantes remotos ejecutar código PHP de su elección mediante el parámetro rootpath en (1) lib/code.php, (2) lib/dbconnect.php, (3) lib/error.php, (4) lib/menu.php, y otros fichero no especificados. NOTA: la procedencia de esta…
ModificadaMedia (5)4.0%—Nullsoft Shoutcast DSP12/7/200616/6/2026
Vulnerabilidad de salto de directorio en Nullsoft SHOUTcast DSP en versiones anteriores a 1.9.7 permite a atacantes remotos leer archivos arbitrarios a través de vectores no especificados que son una "ligera variación" de CVE-2006-3534.
ModificadaAlta (7.8)2.5%—Nullsoft Shoutcast Server12/7/200616/6/2026
Vulnerabilidad de salto de directorio en Nullsoft SHOUTcast DSP versiones anteriores a la 1.9.6, filtra secuencias de salto de directorio antes de decodificarse, lo que permite a atacantes remotos leer ficheros de su elección a través de secuencias codificadas punto punto (%2E%2E) en una petición HTTP GET para una…
ModificadaMedia (4.3)2.0%—Nullsoft Shoutcast Server13/6/200616/6/2026
Múltiples vulnerabilidades de XSS en SHOUTcast 1.9.5 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de los campos DJ (1) Description, (2) URL, (3) Genre, (4) AIM y (5) ICQ.
ModificadaAlta (7.6)7.6%💥 ExploitID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory8/5/200616/6/2026
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.
ModificadaAlta (7.5)73%💥 ExploitPeercast10/3/200616/6/2026
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow remote attackers to execute arbitrary code via an HTTP GET request with a long (1) parameter name or (2) value in a URL, which triggers the overflow in the nextCGIarg function in servhs.cpp.
ModificadaAlta (7.5)1.2%💥 ExploitComdev Vote Caster26/11/200516/6/2026
SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action.
ModificadaAlta (7.5)1.3%💥 ExploitActivecampaign 1-2-all Broadcast Email18/11/200516/6/2026
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
ModificadaAlta (10)1.4%—Flexcast Audio Video Streaming Server9/6/200516/6/2026
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.
ModificadaAlta (7.5)12%💥 ExploitPeercast28/5/200516/6/2026
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.
ModificadaMedia (5)2.6%—Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+62/5/200516/6/2026
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.
ModificadaAlta (7.5)9.4%💥 ExploitIcecast2/5/200516/6/2026
Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.
ModificadaMedia (5)2.5%—Icecast2/5/200516/6/2026
IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).
ModificadaAlta (7.5)1.9%—Castlehill Secure NET20/4/200516/6/2026
Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.
ModificadaAlta (7.5)78%💥 ExploitIcecast31/12/200416/6/2026
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
ModificadaAlta (7.5)70%💥 ExploitNullsoft Shoutcast Server23/12/200416/6/2026
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.
ModificadaMedia (4.3)1.2%—Icecast20/10/200416/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en list.cgi en el servidor web interno de Icecast (icecast-server) 1.3.12 y anteriores permite a atacantes remotos inyectar script web de su elección mediante el parámetro UserAgent.
ModificadaMedia (5)1.7%—Vypress Tonecast19/10/200416/6/2026
Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.
ModificadaMedia (5)2.1%—Icecast10/5/200416/6/2026
Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.