Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.3) | 0.12% | — | Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI | 28/7/2026 | 28/7/2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a… | |
| Analizada | Alta (8.7) | 0.92% | — | Cribl Stream | 27/7/2026 | 20/8/2026 | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's… | |
| Analizada | Alta (8.7) | 0.67% | — | Cribl Stream | 27/7/2026 | 20/8/2026 | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value. | |
| Aplazada | Crítica (9.1) | 0.86% | — | Ammos Instrument Toolkit Binary Stream CaptureAINasa AIT CoreAI | 21/7/2026 | 23/7/2026 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In… | |
| Analizada | Baja (3.3) | 0.15% | — | Oracle Goldengate Stream Analytics | 21/7/2026 | 6/8/2026 | Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate… | |
| Pendiente de análisis | Alta (7.5) | 1.0% | — | GstreamerAI | 9/7/2026 | 19/8/2026 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that… | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | GstreamerAI | 9/7/2026 | 2/9/2026 | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type… | |
| Pendiente de análisis | Baja (3.7) | 0.23% | — | Gstreamer WebrtcbinAI | 7/7/2026 | 8/7/2026 | A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the… | |
| Analizada | Media (4.4) | 0.16% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 6/7/2026 | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first… | |
| Analizada | Media (4.3) | 0.39% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream… | |
| Aplazada | Crítica (9.9) | 0.47% | — | DeepstreamAI | 18/6/2026 | 23/6/2026 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record. This issue has… | |
| Aplazada | Crítica (10) | 0.99% | — | StreambertAI | 17/6/2026 | 17/6/2026 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious… | |
| Aplazada | Media (5.4) | 0.31% | — | WpstreamAI | 15/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions. | |
| Pendiente de análisis | Alta (7.6) | 0.70% | — | Gstreamer Gst-plugins-goodAI | 15/6/2026 | 3/8/2026 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 8/9/2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 5/8/2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel… | |
| Pendiente de análisis | Alta (7.1) | 0.74% | — | GstreamerAI | 15/6/2026 | 3/8/2026 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Gstreamer PcapparseAI | 15/6/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into… | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Gstreamer LibrfbAI | 15/6/2026 | 3/8/2026 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server… | |
| Pendiente de análisis | Alta (7.1) | 0.63% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three… | |
| Analizada | Baja (1.1) | 0.08% | — | Snowflake Streamlit | 4/6/2026 | 22/7/2026 | A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of… | |
| Analizada | Alta (7.5) | 0.45% | — | Shopify React-routerTurbo-stream Turbo Stream | 2/6/2026 | 22/7/2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications… |