Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | — | Grandstream Ucm6202 FirmwareGrandstream Ucm6204 FirmwareGrandstream Ucm6208 Firmware | 30/3/2020 | 17/6/2026 | The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords. | |
| Modificada | Crítica (9.8) | 5.9% | — | Grandstream Ucm6202 FirmwareGrandstream Ucm6204 FirmwareGrandstream Ucm6208 Firmware | 30/3/2020 | 17/6/2026 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges. | |
| Modificada | Alta (7.5) | 2.9% | — | Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Grandstream Ucm6200 Firmware | 23/3/2020 | 17/6/2026 | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17. | |
| Modificada | Crítica (9.8) | 2.6% | — | Closure-compiler-stream Project Closure-compiler-stream | 15/3/2020 | 17/6/2026 | closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+66 | 12/3/2020 | 17/6/2026 | Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html | |
| Modificada | Media (6.7) | 0.34% | — | Intel NUC KIT Nuc8i7bek FirmwareIntel NUC 8 Enthusiast PC Nuc8i7bekqa FirmwareIntel NUC KIT Nuc8i7hnk FirmwareIntel NUC 8 Business PC Nuc8i7hnkqc Firmware+66 | 12/3/2020 | 17/6/2026 | Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html | |
| Modificada | Crítica (9.8) | 4.1% | — | Fasterxml Jackson-databindNetapp Oncommand API ServicesNetapp Steelstore Cloud Integrated StorageOracle Goldengate Stream Analytics | 2/3/2020 | 17/6/2026 | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using… | |
| Modificada | Crítica (9.1) | 2.2% | — | Bosch Video Streaming GatewayBosch Divar IP 2000 FirmwareBosch Divar IP 5000 Firmware | 7/2/2020 | 17/6/2026 | Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all… | |
| Modificada | Alta (7.8) | 0.45% | — | Wowza Streaming Engine | 29/1/2020 | 17/6/2026 | A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files. By injecting a payload into one of those files, it will run with… | |
| Modificada | Media (5.4) | 0.95% | — | Wowza Streaming Engine | 29/1/2020 | 17/6/2026 | Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of the login form. This issue was resolved… | |
| Modificada | Media (6.5) | 0.85% | — | Wowza Streaming Engine | 29/1/2020 | 17/6/2026 | Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza… | |
| Modificada | Crítica (9.8) | 8.6% | — | Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+26 | 3/1/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | |
| Modificada | Media (6.7) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+15 | 16/12/2019 | 17/6/2026 | Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+15 | 16/12/2019 | 17/6/2026 | Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+15 | 16/12/2019 | 17/6/2026 | Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+15 | 16/12/2019 | 17/6/2026 | Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel Nuc8i7bek FirmwareIntel Cd1p64gk Firmware+15 | 16/12/2019 | 17/6/2026 | Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (10) | 2.6% | — | Grandstream Gxv3501 FirmwareGrandstream Gxv3504 FirmwareGrandstream Gxv3601 FirmwareGrandstream Gxv3601hd Firmware+9 | 11/12/2019 | 16/6/2026 | Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel NUC Board De3815tybe FirmwareIntel NUC KIT De3815tykhe Firmware+1 | 11/10/2019 | 17/6/2026 | Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel NUC 8 Mainstream Game KIT FirmwareIntel NUC 8 Mainstream Game Mini Computer FirmwareIntel NUC Board De3815tybe FirmwareIntel NUC KIT De3815tykhe Firmware+1 | 11/10/2019 | 17/6/2026 | Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access. | |
| Modificada | Alta (7.5) | 4.1% | — | S3bubble-amazon-s3-audio-streaming | 10/10/2019 | 17/6/2026 | The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter. | |
| Modificada | Alta (8.8) | 0.56% | — | Vzug Combi-stream Mslq Firmware | 6/10/2019 | 17/6/2026 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control. | |
| Modificada | Crítica (9.1) | 0.67% | — | Vzug Combi-stream Mslq Firmware | 6/10/2019 | 17/6/2026 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service. | |
| Modificada | Alta (8.8) | 0.46% | — | Vzug Combi-stream Mslq Firmware | 6/10/2019 | 17/6/2026 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service. |