Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 3.8% | 💥 Exploit | Podlove Podcast PublisherAI | 14/7/2026 | 14/7/2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Media (6.4) | 0.33% | — | Fresh PodcasterAI | 11/7/2026 | 14/7/2026 | The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Broadcast Live VideoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | |
| Pendiente de análisis | Media (4.5) | 0.12% | — | Mimecast IncydrAI | 5/6/2026 | 23/7/2026 | In Mimecast Incydr before 2.6.0, arbitrary file access can occur. | |
| Aplazada | Alta (7.2) | 0.41% | — | Videowhisper Broadcast Live VideoAI | 25/5/2026 | 24/7/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3. | |
| Aplazada | Media (5.1) | 0.19% | — | Podcastgenerator Podcast GeneratorAI | 15/5/2026 | 17/6/2026 | Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript… | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | SAP Forecasting AND ReplenishmentAI | 12/5/2026 | 17/6/2026 | Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the attacker to read or modify any system data or… | |
| Analizada | Alta (8.8) | 0.57% | — | Azuracast | 9/5/2026 | 24/7/2026 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting… | |
| Analizada | Alta (8.8) | 1.0% | — | Azuracast | 9/5/2026 | 24/7/2026 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the… | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Legion OF THE Bouncy Castle INC Bc-ltsAILegion OF THE Bouncy Castle INC Bc-fjaAI | 8/5/2026 | 21/7/2026 | A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0… | |
| Analizada | Media (6.5) | 1.4% | — | Nokia Broadcast Message Center | 8/5/2026 | 12/8/2026 | Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field. | |
| Aplazada | Alta (8.4) | 0.18% | — | Empia Technology AvacastAI | 28/4/2026 | 17/6/2026 | AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts. | |
| Aplazada | Alta (8.5) | 0.17% | — | Empia Technology AvacastAI | 28/4/2026 | 17/6/2026 | AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL. | |
| Aplazada | Media (5.5) | 0.47% | — | Joecastrom Mcp-chat-studioAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the… | |
| Pendiente de análisis | Alta (8.9) | 0.96% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. | |
| Pendiente de análisis | Media (6.3) | 0.69% | — | Legion OF THE Bouncy Castle INC Bcpix-ltsAIBouncycastle Bc-javaAIBouncycastle Bcpkix-fipsAI | 15/4/2026 | 18/9/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated… | |
| Pendiente de análisis | Alta (8.7) | 0.88% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue… | |
| Pendiente de análisis | Media (5.5) | 0.53% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 18/9/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1,… | |
| Pendiente de análisis | Crítica (9.3) | 0.32% | — | Bouncycastle Bc-javaAI | 15/4/2026 | 7/10/2026 | : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. | |
| Aplazada | Media (5.4) | 0.22% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11. | |
| Aplazada | Media (5.3) | 0.31% | — | Castos Seriously Simple PodcastingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.2. | |
| Modificada | Crítica (9) | 0.57% | — | Uxgroupllc Cast TO TV | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure. | |
| Aplazada | Media (6.5) | 0.26% | — | Albfan MiraclecastAI | 24/3/2026 | 17/6/2026 | NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0. | |
| Aplazada | Alta (8.6) | 0.18% | — | Jetaudio Jetcast ServerAI | 22/3/2026 | 17/6/2026 | JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration field that allows local attackers to overwrite structured exception handling pointers. Attackers can inject alphanumeric encoded shellcode through the Log Directory field to trigger an SEH exception… | |
| Aplazada | Media (6.8) | 0.16% | — | Cowon America Jetcast ServerAI | 22/3/2026 | 17/6/2026 | jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Log directory configuration field. Attackers can paste a buffer of 5000 characters into the Log directory input, then click Start to trigger a crash that… |