Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.98%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
ModificadaAlta (7.8)1.2%💥 ExploitAsrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaAlta (7.5)1.1%—Leostream AgentLeostream Connection Broker30/10/201817/6/2026
The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Leostream Agent API.
ModificadaBaja (3.7)0.73%—Carestream VUE RIS4/10/201817/6/2026
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could use to initiate a more elaborate attack.
ModificadaMedia (5.9)0.91%—Subsonic Music Streamer11/9/201817/6/2026
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data.
ModificadaAlta (7.5)1.8%—Flir Brickstream 2300 Firmware28/6/201817/6/2026
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.
ModificadaAlta (7.5)2.0%—List-n-stream Project List-n-stream7/6/201817/6/2026
list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)8.5%—Apache ZookeeperDebian LinuxOracle Goldengate Stream Analytics21/5/201817/6/2026
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
ModificadaCrítica (9.8)15%—QOS Slf4jRedhat Jboss Enterprise Application PlatformRedhat VirtualizationRedhat Virtualization Host+920/3/201817/6/2026
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
ModificadaMedia (6.1)1.1%—Videowhisper Live Streaming Integration19/3/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.
ModificadaAlta (8.8)0.45%—Qnap Media Streaming Add-on8/3/201817/6/2026
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
ModificadaCrítica (9.8)3.1%—Qnap Media Streaming Add-on8/3/201817/6/2026
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
ModificadaMedia (6.5)0.67%—Qnap Media Streaming Add-on8/3/201817/6/2026
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
ModificadaMedia (6.1)0.76%—Qnap Media Streaming Add-on8/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
ModificadaMedia (5.3)1.4%—Wowza Streaming Engine5/3/201817/6/2026
In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of a file are possible via a remote, specifically crafted HTTP request.
ModificadaMedia (6.1)0.88%—Wowza Streaming Engine1/3/201817/6/2026
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causing script injection and/or reflection via a crafted HTTP request.
ModificadaAlta (7.5)1.5%—Wowza Streaming Engine1/3/201817/6/2026
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.
ModificadaCrítica (9.8)2.3%—Wowza Streaming Engine1/3/201817/6/2026
An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).
ModificadaMedia (5.4)0.66%—Atlassian Activity Streams29/1/201817/6/2026
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are added to the watched page, and vote & watch JIRA issues that they do not have access to, although they will not receive…
ModificadaCrítica (9.8)1.2%—Flir Brickstream 2300 2D FirmwareFlir Brickstream 2300 3D FirmwareFlir Brickstream 2300 3D+ Firmware1/1/201817/6/2026
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a direct request.
ModificadaAlta (7.5)1.5%—Streamrelay1/12/201717/6/2026
StreamRelay.NET.exe ver2.14.0.7 and earlier allows remote attackers to cause a denial of service via unspecified vectors.
ModificadaAlta (8.8)0.49%—Grandstream Ht802 Firmware6/11/201717/6/2026
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
ModificadaMedia (5.4)0.61%—Grandstream Ht802 Firmware6/11/201717/6/2026
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).
ModificadaAlta (8)0.44%—Grandstream Ht802 Firmware6/11/201717/6/2026
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
AnalizadaAlta (8.1)99%⚠ Explotación activa💥 ExploitApache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+315/9/201717/6/2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Orbitaley — Vulnerabilidades