Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.44% | — | Xiph Vorbis-tools | 2/10/2023 | 17/6/2026 | Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files. | |
| Modificada | Media (4.3) | 0.56% | — | Themeisle Orbitfox | 30/5/2023 | 17/6/2026 | The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing. | |
| Modificada | Media (4.8) | 0.39% | — | Snaborbital Panorama | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <= 1.5 versions. | |
| Modificada | Alta (7.5) | 0.70% | — | Fileorbis | 13/1/2023 | 17/6/2026 | Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3. | |
| Modificada | Media (6.1) | 0.97% | — | Cisco Orbital | 6/10/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker to redirect users to a malicious webpage. This vulnerability is due to improper validation of URL paths in the web-based management interface. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.5) | 0.90% | — | Themeisle Orbit FOX | 5/4/2021 | 17/6/2026 | Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however,… | |
| Modificada | Media (5.4) | 0.69% | — | Themeisle Orbit FOX | 5/4/2021 | 17/6/2026 | Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious. | |
| Modificada | Media (6.5) | 1.0% | — | StepmaniaXiph.org Libvorbis | 26/12/2020 | 17/6/2026 | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146. | |
| Modificada | Alta (8.8) | 0.77% | — | Orbisius Child Theme Creator | 16/11/2020 | 17/6/2026 | The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file. | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Xorbin Analog Flash Clock | 27/12/2019 | 16/6/2026 | Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS | |
| Modificada | Media (6.1) | 1.3% | — | Xorbin Digital Flash Clock | 27/12/2019 | 16/6/2026 | WordPress Xorbin Digital Flash Clock 1.0 has XSS | |
| Modificada | Crítica (9.8) | 1.3% | — | Orbitz | 15/10/2019 | 17/6/2026 | In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat. | |
| Modificada | Media (6.5) | 1.4% | — | Orbisius Child Theme Creator | 7/10/2019 | 17/6/2026 | The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter. | |
| Modificada | Media (5.5) | 0.96% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.1) | 0.98% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.8) | 1.5% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.1) | 0.98% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. | |
| Modificada | Media (5.5) | 0.96% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Media (5.5) | 1.0% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. | |
| Modificada | Alta (7.8) | 1.5% | — | STB Vorbis Project STB VorbisDebian Linux | 15/8/2019 | 17/6/2026 | A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. | |
| Modificada | Media (5.5) | 0.32% | — | Orbic Wonder Rc555l Firmware | 29/8/2018 | 17/6/2026 | An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing attackers to obtain sensitive information (such as text-message content) by reading a copy of the Android log on the SD card. The system-wide Android logs are not directly available to third-party apps… | |
| Modificada | Alta (7.1) | 0.26% | — | Orbic Wonder Rc555l Firmware | 29/8/2018 | 17/6/2026 | An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-located on the device can send an intent to factory reset the device programmatically because of com.android.server.MasterClearReceiver. This does not require any user interaction and does not require… | |
| Modificada | Alta (7.5) | 2.4% | — | Xiph.org LibvorbisDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 26/4/2018 | 17/6/2026 | bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. | |
| Modificada | Alta (8.8) | 3.3% | — | Xiph.org LibvorbisDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 26/4/2018 | 17/6/2026 | mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Alta (8.8) | 1.8% | — | STB Vorbis Project STB Vorbis | 9/2/2018 | 17/6/2026 | Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via Victim must open a specially crafted Ogg Vorbis file. This… |