Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
–

2802 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.49%—Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r2/12/202517/6/2026
In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689251;…
AnalizadaMedia (5.3)0.49%—Mediatek Nr15Mediatek Nr162/12/202517/6/2026
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689252; Issue…
ModificadaMedia (6.5)0.24%—Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r2/12/202517/6/2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01270690; Issue…
ModificadaMedia (6.5)0.24%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a una falta de verificación de límites. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción…
ModificadaMedia (6.5)0.24%—Mediatek Nr152/12/202517/6/2026
En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría conducir a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción…
AnalizadaMedia (5.3)0.37%—Mediatek Nr152/12/202525/9/2026
En el Módem, existe una posible caída de la aplicación debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita…
AnalizadaMedia (6.5)0.30%—Live555 Streaming Media1/12/202517/6/2026
A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.
AnalizadaMedia (6.5)0.30%—Live555 Streaming Media1/12/202517/6/2026
A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.
AnalizadaMedia (6.5)0.33%—Live555 Streaming Media1/12/202517/6/2026
A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file.
AnalizadaMedia (6.5)0.30%—Live555 Streaming Media1/12/202517/6/2026
A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.
AnalizadaMedia (6.5)0.33%—Live555 Streaming Media1/12/202517/6/2026
A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.
AplazadaMedia (6.9)0.35%—MediacrushAI1/12/20253/9/2026
A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.
AplazadaAlta (8.7)0.53%—Dongyoung Media Dm-ap240t/wAI26/11/202517/6/2026
Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed…
AplazadaMedia (4.3)0.23%—Najeebmedia Frontend File ManagerAI25/11/202517/6/2026
The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for…
AplazadaMedia (6.4)0.18%—Coatedmedia User Profile BuilderAI19/11/202517/6/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied…
AnalizadaMedia (4.3)0.26%—Maykinmedia Open Forms18/11/202517/6/2026
Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to readonly/disabled can be modified by malicious users deliberately trying to modify data they're not supposed to. For regular users, the form fields are marked as…
AplazadaAlta (8.7)0.46%—Request Serious Play F3 Media ServerAI14/11/202517/6/2026
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption…
AplazadaMedia (4.3)0.19%—Nmedia Frontend File ManagerAI13/11/20257/10/2026
Vulnerabilidad de autorización faltante en N-Media Frontend File Manager nmedia-user-file-uploader permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Frontend File Manager: desde n/a hasta menor o igual que 23.2.
ModificadaMedia (6.7)0.18%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432679; Issue ID: MSV-3950.
AnalizadaAlta (8)0.30%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949.
AnalizadaMedia (6.7)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958.
AnalizadaMedia (4.7)0.10%—Mediatek Software Development KIT4/11/202517/6/2026
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036.
AnalizadaMedia (6.7)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038.
AnalizadaMedia (6.7)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435342; Issue ID: MSV-4039.
AnalizadaAlta (7.8)0.16%—Mediatek Software Development KITOpenwrt4/11/202517/6/2026
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040.