Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.94% | — | Meetecho Janus | 16/12/2021 | 17/6/2026 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.84% | — | Meetecho Janus | 27/11/2021 | 17/6/2026 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.2) | 0.28% | — | Amazon Echo DOT Firmware | 24/7/2021 | 17/6/2026 | Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Echobh Sharecare | 13/7/2021 | 17/6/2026 | An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection. | |
| Modificada | Media (6.5) | 0.77% | — | Echobh Sharecare | 13/7/2021 | 17/6/2026 | An issue was discovered in Echo ShareCare 8.15.5. The TextReader feature in General/TextReader/TextReader.cfm is susceptible to a local file inclusion vulnerability when processing remote input in the textFile parameter from an authenticated user, leading to the ability to read arbitrary files on the server… | |
| Modificada | Alta (8.8) | 1.0% | — | Echobh Sharecare | 13/7/2021 | 17/6/2026 | An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the ability to inject arbitrary arguments to… | |
| Modificada | Alta (8.8) | 2.1% | — | Echobh Sharecare | 13/7/2021 | 17/6/2026 | An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via the name1 parameter, when processing remote input from an authenticated user, leading to the ability for arbitrary files to be written to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Echobh Sharecare | 13/7/2021 | 17/6/2026 | Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data. | |
| Modificada | Alta (7.5) | 2.3% | — | Vfsjfilechooser2 Project Vfsjfilechooser2 | 21/6/2021 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 2.3% | — | Meetecho Janus | 15/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet. | |
| Modificada | Crítica (9.8) | 1.9% | — | Meetecho Janus | 15/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server. | |
| Modificada | Crítica (9.8) | 2.6% | — | Meetecho Janus | 10/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow. | |
| Modificada | Alta (7.5) | 2.4% | — | Meetecho Janus | 10/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_preparse in sdp.c has a NULL pointer dereference. | |
| Modificada | Alta (7.5) | 2.1% | — | Meetecho Janus | 10/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory. | |
| Modificada | Alta (7.5) | 2.3% | — | Meetecho Janus | 10/6/2020 | 17/6/2026 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference. | |
| Modificada | Media (4.8) | 0.47% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions. | |
| Modificada | Media (5.9) | 0.65% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash. | |
| Modificada | Media (4.2) | 0.47% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times. | |
| Modificada | Crítica (9.8) | 1.4% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation. | |
| Modificada | Alta (7.5) | 0.97% | — | Meetecho Janus | 14/3/2020 | 17/6/2026 | An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge. | |
| Modificada | Media (6.1) | 1.4% | — | Smackcoders Echo Sign | 17/9/2019 | 17/6/2026 | The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter. | |
| Modificada | Media (6.1) | 1.4% | — | Smackcoders Echo Sign | 17/9/2019 | 17/6/2026 | The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter. | |
| Modificada | Crítica (9.8) | 3.5% | — | Typecho | 29/10/2018 | 17/6/2026 | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. |