Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header. | |
| Modificada | Media (6.1) | 0.80% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter. | |
| Modificada | Media (5.3) | 0.93% | — | Vivotek Camera | 3/1/2019 | 17/6/2026 | Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter. | |
| Modificada | Alta (8.8) | 3.0% | — | Vivotek Camera | 5/9/2018 | 17/6/2026 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi. | |
| Modificada | Alta (8.8) | 3.0% | — | Vivotek Camera | 5/9/2018 | 17/6/2026 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/onvif/device_service). | |
| Modificada | Alta (8.8) | 0.47% | — | Vivotek Camera | 5/9/2018 | 17/6/2026 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF. | |
| Modificada | Alta (8.8) | 2.9% | — | Vivotek Camera | 29/8/2018 | 17/6/2026 | Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.90% | — | Voten | 5/3/2018 | 17/6/2026 | An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript. | |
| Modificada | Alta (7.5) | 69% | — | Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware | 23/6/2017 | 17/6/2026 | '/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera… | |
| Modificada | Crítica (9.8) | 82% | — | Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware | 23/6/2017 | 17/6/2026 | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most… | |
| Modificada | Media (5.9) | 0.60% | — | Gocivix Indiana Voters | 15/5/2017 | 17/6/2026 | The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.3% | — | Cdnvote Project Cdnvote | 1/1/2015 | 16/6/2026 | Multiple SQL injection vulnerabilities in cdnvote-post.php in the cdnvote plugin before 0.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) cdnvote_post_id or (2) cdnvote_point parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Votecount FOR Balatarin Project Votecount FOR Balatarin | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount for Balatarin plugin 0.1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) bvcurl parameter. | |
| Modificada | Baja (3.5) | 1.6% | — | Marvil07 Vote UP Down | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms. | |
| Modificada | Media (5) | 1.4% | — | Debian Devotee | 20/8/2012 | 16/6/2026 | devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Ecomstudio PHP Photo Vote1.3f | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Scriptsez Good/bad Vote | 10/3/2010 | 16/6/2026 | Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Scriptsez Good/bad Vote | 10/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action. | |
| Modificada | Media (4.3) | 0.85% | — | Francisco Cifuentes Vote FOR TT News | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Francisco Cifuentes Vote FOR TT News | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Biglle Vote FOR US Extension | 1/7/2009 | 16/6/2026 | SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Activewebsoftwares Activevotes | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Activewebsoftwares Activevotes | 8/12/2008 | 16/6/2026 | SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter. | |
| Modificada | Alta (9.3) | 7.1% | 💥 Exploit | 4xem Vatctrl ClassD-link Mpeg4 SHM Audio ControlVivotek Rtsp Mpeg4 SP Control | 28/10/2008 | 16/6/2026 | Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers… | |
| Modificada | Media (4.3) | 1.0% | — | TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+6 | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and… |