Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.16% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin… | |
| Analizada | Alta (8.7) | 0.21% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true'… | |
| Analizada | Alta (8.5) | 0.21% | — | Wowza Streaming Engine | 16/3/2026 | 17/6/2026 | Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine… | |
| Aplazada | Media (6.3) | 0.25% | — | Streamsoft PrestizAI | 12/3/2026 | 17/6/2026 | Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92. | |
| Analizada | Crítica (9.3) | 41% | 💥 Exploit | Grandstream Gxp1610 FirmwareGrandstream Gxp1615 FirmwareGrandstream Gxp1620 FirmwareGrandstream Gxp1625 Firmware+2 | 18/2/2026 | 17/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the… | |
| Analizada | Baja (2) | 0.60% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: Media Streaming… | |
| Analizada | Baja (1.7) | 0.11% | — | Qnap Media Streaming Add-on | 11/2/2026 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |
| Aplazada | Alta (8.4) | 0.38% | — | Streamripper32AI | 3/2/2026 | 17/6/2026 | StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the application. | |
| Aplazada | Alta (7.1) | 0.23% | — | Mini-stream RM DownloaderAI | 30/1/2026 | 17/6/2026 | RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload with an egg hunter technique to bypass memory protections and execute commands like launching calc.exe. | |
| Aplazada | Alta (8.2) | 0.33% | — | Ricoh Streamline NXAI | 9/1/2026 | 17/6/2026 | Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may… | |
| Aplazada | Alta (8.7) | 0.47% | — | Flir Thermal Camera F FC PT D Stream FirmwareAI | 8/1/2026 | 17/6/2026 | FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across multiple camera series without… | |
| Analizada | Alta (8.1) | 15% | — | Apache Streampipes | 1/1/2026 | 1/10/2026 | A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnerability allows an attacker to gain administrative control over the application by… | |
| Aplazada | Media (4.3) | 0.12% | — | Channelize Live Shopping Video StreamsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Modificada | Alta (8.5) | 4.2% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the traceroute.php script, which triggers the… | |
| Analizada | Crítica (9.3) | 3.7% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands. | |
| Analizada | Alta (8.7) | 3.1% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute… | |
| Modificada | Alta (8.7) | 1.6% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device. | |
| Modificada | Alta (8.5) | 3.8% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, which triggers the… | |
| Modificada | Media (6.9) | 0.79% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without… | |
| Modificada | Alta (8.5) | 4.2% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php… | |
| Analizada | Media (6.9) | 0.83% | — | Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication. | |
| Analizada | Media (5.3) | 0.44% | — | Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions… | |
| Modificada | Crítica (9.3) | 0.60% | — | Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring… | |
| Modificada | Alta (8.7) | 0.80% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting external hosts. | |
| Modificada | Alta (8.8) | 0.89% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database… |