Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.7% | — | Typo3 Pharstreamwrapper | 9/5/2019 | 17/6/2026 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism. | |
| Modificada | Alta (8.8) | 5.9% | — | GstreamerDebian LinuxCanonical Ubuntu Linux | 24/4/2019 | 17/6/2026 | GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+2 | 1/4/2019 | 17/6/2026 | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell. | |
| Modificada | Crítica (9.8) | 1.6% | — | Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+2 | 1/4/2019 | 17/6/2026 | A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device. | |
| Modificada | Media (5.3) | 0.70% | — | Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+2 | 1/4/2019 | 17/6/2026 | A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext. | |
| Modificada | Alta (8.8) | 28% | — | Grandstream Ucm6204 Firmware | 30/3/2019 | 17/6/2026 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI. | |
| Modificada | Alta (8.8) | 44% | — | Grandstream Ucm6204 Firmware | 30/3/2019 | 17/6/2026 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI. | |
| Modificada | Crítica (9.8) | 1.8% | — | Grandstream Gxv3611ir HD Firmware | 30/3/2019 | 17/6/2026 | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. | |
| Modificada | Alta (8.8) | 2.6% | — | Grandstream Gxv3611ir HD Firmware | 30/3/2019 | 17/6/2026 | Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field. | |
| Modificada | Alta (8.8) | 2.6% | — | Grandstream Gxv3370 FirmwareGrandstream Wp820 Firmware | 30/3/2019 | 17/6/2026 | Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field. | |
| Modificada | Alta (8.8) | 2.6% | — | Grandstream Gwn7610 Firmware | 30/3/2019 | 17/6/2026 | Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call. | |
| Modificada | Media (6.5) | 1.5% | — | Grandstream Gwn7610 FirmwareGrandstream Gwn7000 Firmware | 30/3/2019 | 17/6/2026 | Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request. | |
| Modificada | Alta (8.8) | 3.9% | — | Grandstream Gwn7000 Firmware | 30/3/2019 | 17/6/2026 | Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Grandstream Gac2500 FirmwareGrandstream Gvc3202 FirmwareGrandstream Gxv3275 FirmwareGrandstream Gxv3240 Firmware+1 | 30/3/2019 | 17/6/2026 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie… | |
| Modificada | Alta (7.5) | 12% | 💥 PoC | Apache ActivemqNetapp E-series Santricity WEB ServicesOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+4 | 28/3/2019 | 17/6/2026 | In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. | |
| Modificada | Crítica (9.1) | 22% | 💥 Exploit | Wowza Streaming Engine | 21/3/2019 | 17/6/2026 | The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request. | |
| Modificada | Media (5.9) | 0.87% | — | IBM Infosphere Streams | 21/3/2019 | 17/6/2026 | IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Screen Stream Project Screen Stream | 15/3/2019 | 17/6/2026 | The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous /start-stop requests. | |
| Modificada | Crítica (9.8) | 2.2% | — | Live555 Streaming MediaOpensuse Backports SLEOpensuse LeapDebian Linux | 28/2/2019 | 17/6/2026 | In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function. | |
| Modificada | Alta (7.5) | 1.6% | — | Live555 Streaming Media | 11/2/2019 | 17/6/2026 | In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove. | |
| Modificada | Alta (7.5) | 1.4% | — | Live555 Streaming Media | 11/2/2019 | 17/6/2026 | In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed. | |
| Modificada | Crítica (9.8) | 3.2% | — | Live555 Streaming MediaDebian Linux | 4/2/2019 | 17/6/2026 | liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact. | |
| Modificada | Media (5.3) | 1.7% | — | IBM Event Streams | 18/12/2018 | 17/6/2026 | IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507. | |
| Modificada | Alta (7.8) | 1.3% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated… | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled | 30/10/2018 | 17/6/2026 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code. |