Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)12%—Grandstream Ucm6202 FirmwareGrandstream Ucm6204 FirmwareGrandstream Ucm6208 Firmware30/3/202017/6/2026
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
ModificadaCrítica (9.8)5.9%—Grandstream Ucm6202 FirmwareGrandstream Ucm6204 FirmwareGrandstream Ucm6208 Firmware30/3/202017/6/2026
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
ModificadaAlta (7.5)2.9%—Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap27/3/202017/6/2026
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
AnalizadaCrítica (9.8)84%⚠ Explotación activa💥 ExploitGrandstream Ucm6200 Firmware23/3/202017/6/2026
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
ModificadaCrítica (9.8)2.6%—Closure-compiler-stream Project Closure-compiler-stream15/3/202017/6/2026
closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.
ModificadaAlta (7.8)0.34%—Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+6612/3/202017/6/2026
Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
ModificadaMedia (6.7)0.34%—Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+6612/3/202017/6/2026
Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
ModificadaCrítica (9.8)4.1%—Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Steelstore Cloud Integrated StorageOracle Goldengate Stream Analytics2/3/202017/6/2026
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using…
ModificadaCrítica (9.1)2.2%—Bosch Video Streaming GatewayBosch Divar IP 2000 FirmwareBosch Divar IP 5000 Firmware7/2/202017/6/2026
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all…
ModificadaAlta (7.8)0.45%—Wowza Streaming Engine29/1/202017/6/2026
A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files. By injecting a payload into one of those files, it will run with…
ModificadaMedia (5.4)0.95%—Wowza Streaming Engine29/1/202017/6/2026
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of the login form. This issue was resolved…
ModificadaMedia (6.5)0.85%—Wowza Streaming Engine29/1/202017/6/2026
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza…
ModificadaCrítica (9.8)8.6%—Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+263/1/202017/6/2026
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
ModificadaMedia (6.7)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+1516/12/201917/6/2026
Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+1516/12/201917/6/2026
Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+1516/12/201917/6/2026
Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+1516/12/201917/6/2026
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+1516/12/201917/6/2026
Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (10)2.6%—Grandstream Gxv3501 FirmwareGrandstream Gxv3504 FirmwareGrandstream Gxv3601 FirmwareGrandstream Gxv3601hd Firmware+911/12/201916/6/2026
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.
ModificadaAlta (7.8)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel NUC Board De3815tybe FirmwareIntel NUC KIT De3815tykhe Firmware+111/10/201917/6/2026
Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
ModificadaAlta (7.8)0.34%—Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel NUC Board De3815tybe FirmwareIntel NUC KIT De3815tykhe Firmware+111/10/201917/6/2026
Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
ModificadaAlta (7.5)4.1%—S3bubble-amazon-s3-audio-streaming10/10/201917/6/2026
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
ModificadaAlta (8.8)0.56%—Vzug Combi-stream Mslq Firmware6/10/201917/6/2026
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.
ModificadaCrítica (9.1)0.67%—Vzug Combi-stream Mslq Firmware6/10/201917/6/2026
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service.
ModificadaAlta (8.8)0.46%—Vzug Combi-stream Mslq Firmware6/10/201917/6/2026
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.
Orbitaley — Vulnerabilidades