Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.53%—Pingvin Share XAI12/5/202617/6/2026
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the…
AplazadaAlta (8.8)1.2%—Geovision Gv-aswebAI6/5/202617/6/2026
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server by sending a crafted HTTP POST request to the ASWebCommon.srf backend endpoint to bypass the frontend restrictions.
AnalizadaCrítica (9)0.75%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. #### Stack-overflow via unconstrained sscanf The…
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS…
ModificadaCrítica (9.3)0.36%—Geovision Gv-ip Device Utility4/5/202617/6/2026
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on…
ModificadaCrítica (9.8)1.00%—Geovision Gv-vms Firmware4/5/202617/6/2026
A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
AplazadaCrítica (10)0.87%—Geovision Gv-vmsAI4/5/202617/6/2026
GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and…
ModificadaCrítica (9.9)0.62%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
ModificadaMedia (6.5)0.50%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.
AnalizadaMedia (6.1)0.34%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
ModificadaAlta (7.5)0.57%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
ModificadaAlta (8.8)3.3%—Geovision Gv-lpc2011 FirmwareGeovision Gv-lpc2211 Firmware4/5/202617/6/2026
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.
AplazadaCrítica (9.3)0.31%—Geovision Gv-ip Device UtilityAI27/4/202617/6/2026
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on…
AplazadaAlta (8.1)0.95%—Gvectors WpforoAI20/4/202617/6/2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type custom profile fields, allowing authenticated users to store an arbitrary path…
AplazadaMedia (6.5)0.45%—Gvectors WpforoAI17/4/202617/6/2026
The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the `edit()` method of `classes/Posts.php` in all versions up to, and including, 2.4.16. The `post_edit` action handler in `Actions.php` passes…
AplazadaAlta (7.1)0.63%—Gvectors WpforoAI11/4/202617/6/2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without restricting which…
AplazadaCrítica (9.8)1.3%—Dsgvo Google WEB Fonts GdprAI8/4/202624/7/2026
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a…
AplazadaAlta (8.8)0.58%—Gvectors WpforoAI4/4/202624/7/2026
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above, to delete…
AplazadaMedia (6.4)0.33%—Dsgvo Snippet FOR Leaflet MAP AND ITS ExtensionsAI26/3/202617/6/2026
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on user supplied…
AnalizadaAlta (8.8)0.41%—Linkingvision Rapidvms24/3/202617/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
AnalizadaAlta (8.8)0.41%—Linkingvision Rapidvms24/3/202617/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
AnalizadaAlta (7.8)0.16%—Linkingvision Rapidvms24/3/202617/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
AplazadaCrítica (9.1)0.72%—WP Dsgvo ToolsAI24/3/202617/6/2026
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and…
AplazadaCrítica (10)0.41%—GV Edge Recording ManagerAI23/3/202617/6/2026
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. During installation, ERM creates a Windows service that runs under the LocalSystem account. When the ERM application is launched, related…
AnalizadaMedia (6.9)0.32%—Gvectors Wpdiscuz13/3/202617/6/2026
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can exploit LIKE wildcard characters in the…