Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.80%—Vivotek Camera3/1/201917/6/2026
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
ModificadaMedia (6.1)0.80%—Vivotek Camera3/1/201917/6/2026
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.
ModificadaMedia (5.3)0.93%—Vivotek Camera3/1/201917/6/2026
Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.
ModificadaAlta (8.8)3.0%—Vivotek Camera5/9/201817/6/2026
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.
ModificadaAlta (8.8)3.0%—Vivotek Camera5/9/201817/6/2026
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/onvif/device_service).
ModificadaAlta (8.8)0.47%—Vivotek Camera5/9/201817/6/2026
VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.
ModificadaAlta (8.8)2.9%—Vivotek Camera29/8/201817/6/2026
Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code.
ModificadaMedia (6.1)0.90%—Voten5/3/201817/6/2026
An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template literal in the bio field of a user profile (resources/views/layouts/app.blade.php) allows for server-side template injection of arbitrary JavaScript.
ModificadaAlta (7.5)69%—Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware23/6/201717/6/2026
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera…
ModificadaCrítica (9.8)82%—Vivotek Network Camera Ib8369 FirmwareVivotek Network Camera Fd8164 FirmwareVivotek Network Camera Fd816ba Firmware23/6/201717/6/2026
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most…
ModificadaMedia (5.9)0.60%—Gocivix Indiana Voters15/5/201717/6/2026
The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.3%—Cdnvote Project Cdnvote1/1/201516/6/2026
Multiple SQL injection vulnerabilities in cdnvote-post.php in the cdnvote plugin before 0.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) cdnvote_post_id or (2) cdnvote_point parameter.
ModificadaMedia (4.3)1.6%—Votecount FOR Balatarin Project Votecount FOR Balatarin2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount for Balatarin plugin 0.1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) bvcurl parameter.
ModificadaBaja (3.5)1.6%—Marvil07 Vote UP Down20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.
ModificadaMedia (5)1.4%—Debian Devotee20/8/201216/6/2026
devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack.
ModificadaMedia (4.3)1.5%💥 ExploitEcomstudio PHP Photo Vote1.3f11/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in login.php in PHP Photo Vote 1.3F allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaAlta (7.5)2.4%💥 ExploitScriptsez Good/bad Vote10/3/201016/6/2026
Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.4%💥 ExploitScriptsez Good/bad Vote10/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.
ModificadaMedia (4.3)0.85%—Francisco Cifuentes Vote FOR TT News15/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.0%—Francisco Cifuentes Vote FOR TT News15/1/201016/6/2026
SQL injection vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)0.92%💥 ExploitBiglle Vote FOR US Extension1/7/200916/6/2026
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.
ModificadaAlta (7.5)1.00%💥 ExploitActivewebsoftwares Activevotes17/12/200816/6/2026
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitActivewebsoftwares Activevotes8/12/200816/6/2026
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
ModificadaAlta (9.3)7.1%💥 Exploit4xem Vatctrl ClassD-link Mpeg4 SHM Audio ControlVivotek Rtsp Mpeg4 SP Control28/10/200816/6/2026
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers…
ModificadaMedia (4.3)1.0%—TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+622/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and…
Orbitaley — Vulnerabilidades