Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
2802 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.49% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689251;… | |
| Analizada | Media (5.3) | 0.49% | — | Mediatek Nr15Mediatek Nr16 | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689252; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15Mediatek Nr16Mediatek Nr17Mediatek Nr17r | 2/12/2025 | 17/6/2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01270690; Issue… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una falta de verificación de límites. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Modificada | Media (6.5) | 0.24% | — | Mediatek Nr15 | 2/12/2025 | 17/6/2026 | En el Módem, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría conducir a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Analizada | Media (5.3) | 0.37% | — | Mediatek Nr15 | 2/12/2025 | 25/9/2026 | En el Módem, existe una posible caída de la aplicación debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota, si un UE se ha conectado a una estación base maliciosa controlada por el atacante, sin necesidad de privilegios de ejecución adicionales. No se necesita… | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream. | |
| Aplazada | Media (6.9) | 0.35% | — | MediacrushAI | 1/12/2025 | 3/9/2026 | A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely. | |
| Aplazada | Alta (8.7) | 0.53% | — | Dongyoung Media Dm-ap240t/wAI | 26/11/2025 | 17/6/2026 | Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without requiring authentication or authorization. The exposed… | |
| Aplazada | Media (4.3) | 0.23% | — | Najeebmedia Frontend File ManagerAI | 25/11/2025 | 17/6/2026 | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Media (4.3) | 0.26% | — | Maykinmedia Open Forms | 18/11/2025 | 17/6/2026 | Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to readonly/disabled can be modified by malicious users deliberately trying to modify data they're not supposed to. For regular users, the form fields are marked as… | |
| Aplazada | Alta (8.7) | 0.46% | — | Request Serious Play F3 Media ServerAI | 14/11/2025 | 17/6/2026 | ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption… | |
| Aplazada | Media (4.3) | 0.19% | — | Nmedia Frontend File ManagerAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en N-Media Frontend File Manager nmedia-user-file-uploader permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Frontend File Manager: desde n/a hasta menor o igual que 23.2. | |
| Modificada | Media (6.7) | 0.18% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432679; Issue ID: MSV-3950. | |
| Analizada | Alta (8) | 0.30% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949. | |
| Analizada | Media (6.7) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958. | |
| Analizada | Media (4.7) | 0.10% | — | Mediatek Software Development KIT | 4/11/2025 | 17/6/2026 | In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036. | |
| Analizada | Media (6.7) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038. | |
| Analizada | Media (6.7) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435342; Issue ID: MSV-4039. | |
| Analizada | Alta (7.8) | 0.16% | — | Mediatek Software Development KITOpenwrt | 4/11/2025 | 17/6/2026 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040. |