Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.7%—Typo3 Pharstreamwrapper9/5/201917/6/2026
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
ModificadaAlta (8.8)5.9%—GstreamerDebian LinuxCanonical Ubuntu Linux24/4/201917/6/2026
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
ModificadaCrítica (9.8)1.9%—Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+21/4/201917/6/2026
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
ModificadaCrítica (9.8)1.6%—Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+21/4/201917/6/2026
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
ModificadaMedia (5.3)0.70%—Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+21/4/201917/6/2026
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
ModificadaAlta (8.8)28%—Grandstream Ucm6204 Firmware30/3/201917/6/2026
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
ModificadaAlta (8.8)44%—Grandstream Ucm6204 Firmware30/3/201917/6/2026
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
ModificadaCrítica (9.8)1.8%—Grandstream Gxv3611ir HD Firmware30/3/201917/6/2026
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
ModificadaAlta (8.8)2.6%—Grandstream Gxv3611ir HD Firmware30/3/201917/6/2026
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
ModificadaAlta (8.8)2.6%—Grandstream Gxv3370 FirmwareGrandstream Wp820 Firmware30/3/201917/6/2026
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.
ModificadaAlta (8.8)2.6%—Grandstream Gwn7610 Firmware30/3/201917/6/2026
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.
ModificadaMedia (6.5)1.5%—Grandstream Gwn7610 FirmwareGrandstream Gwn7000 Firmware30/3/201917/6/2026
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
ModificadaAlta (8.8)3.9%—Grandstream Gwn7000 Firmware30/3/201917/6/2026
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.
ModificadaCrítica (9.8)15%💥 ExploitGrandstream Gac2500 FirmwareGrandstream Gvc3202 FirmwareGrandstream Gxv3275 FirmwareGrandstream Gxv3240 Firmware+130/3/201917/6/2026
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie…
ModificadaAlta (7.5)12%💥 PoCApache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+428/3/201917/6/2026
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
ModificadaCrítica (9.1)22%💥 ExploitWowza Streaming Engine21/3/201917/6/2026
The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.
ModificadaMedia (5.9)0.87%—IBM Infosphere Streams21/3/201917/6/2026
IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.
ModificadaAlta (7.5)10%💥 ExploitScreen Stream Project Screen Stream15/3/201917/6/2026
The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous /start-stop requests.
ModificadaCrítica (9.8)2.2%—Live555 Streaming MediaOpensuse Backports SLEOpensuse LeapDebian Linux28/2/201917/6/2026
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
ModificadaAlta (7.5)1.6%—Live555 Streaming Media11/2/201917/6/2026
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
ModificadaAlta (7.5)1.4%—Live555 Streaming Media11/2/201917/6/2026
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.
ModificadaCrítica (9.8)3.2%—Live555 Streaming MediaDebian Linux4/2/201917/6/2026
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.
ModificadaMedia (5.3)1.7%—IBM Event Streams18/12/201817/6/2026
IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.
ModificadaAlta (7.8)1.3%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaAlta (7.8)1.5%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.