Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.57% | — | Ezviz Internet PT Camera Cs-cv246AI | 23/8/2024 | 5/7/2026 | Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol… | |
| Modificada | Media (6.1) | 0.42% | 💥 PoC | Heytap Internet Browser | 19/8/2024 | 17/6/2026 | The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component. | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.32% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.48% | — | Comodo Internet Security | 29/7/2024 | 17/6/2026 | Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order… | |
| Modificada | Media (5.5) | 0.20% | — | Eset Internet SecurityEset Nod32Eset SecurityEset Smart Security+4 | 16/7/2024 | 17/6/2026 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were met. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Internet2 GrouperAIInternet2 Grouper FOR WEB ServicesAI | 29/6/2024 | 17/6/2026 | Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1. | |
| Aplazada | Media (6.8) | 0.34% | — | Paradox Ip150 Internet ModuleAI | 19/6/2024 | 17/6/2026 | The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system. | |
| Analizada | Media (5.5) | 0.15% | — | Samsung Internet | 7/5/2024 | 17/6/2026 | Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies. | |
| Analizada | Alta (7.8) | 0.20% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 1/4/2024 | 17/6/2026 | A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total… | |
| Aplazada | Media (6.3) | 0.20% | — | Fujifilm Centreware Internet ServicesAIFujifilm Internet ServicesAI | 18/3/2024 | 17/6/2026 | Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. As… | |
| Analizada | Alta (7.8) | 0.18% | — | Samsung Internet | 5/3/2024 | 17/6/2026 | Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code. | |
| Analizada | Media (5.3) | 0.15% | — | Samsung Internet | 5/3/2024 | 17/6/2026 | Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction. | |
| Analizada | Media (5.3) | 0.35% | — | Samsung Internet | 5/3/2024 | 17/6/2026 | Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction. | |
| Modificada | Alta (7.8) | 0.55% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 15/2/2024 | 17/6/2026 | Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission. | |
| Modificada | Media (4.6) | 0.24% | — | Samsung Internet | 6/2/2024 | 17/6/2026 | Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication. | |
| Modificada | Alta (7.5) | 0.34% | — | Zscaler Secure Internet AND Saas Access | 31/1/2024 | 17/6/2026 | In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic. | |
| Modificada | Media (5.5) | 0.28% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+2 | 31/1/2024 | 17/6/2026 | Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions. | |
| Modificada | Alta (7.8) | 0.64% | — | Trendmicro AIR SupportTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum Security+1 | 29/1/2024 | 17/6/2026 | Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate… | |
| Modificada | Media (6.1) | 0.51% | — | Martmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The manipulation of the argument Client Full Name with the input <meta http-equiv="refresh" content="0; url=https://vuldb.com" /> leads to open… | |
| Modificada | Media (5.4) | 0.56% | — | Martinmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. The manipulation of the argument Client Full Name leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.74% | — | Codeastro Internet Banking System | 2/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Modificada | Alta (8.6) | 0.38% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+5 | 21/12/2023 | 17/6/2026 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or SHA1 algorithm as trusted. | |
| Modificada | Media (5.4) | 0.39% | — | Bainternet Shortcodes UI | 8/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions. |