Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.46% | — | Dell ECS Streamer | 26/7/2023 | 17/6/2026 | Dell ECS Streamer, versions prior to 2.0.7.1, contain an insertion of sensitive information in log files vulnerability. A remote malicious high-privileged user could potentially exploit this vulnerability leading to exposure of this sensitive data. | |
| Modificada | Alta (7.8) | 0.46% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap… | |
| Modificada | Alta (7.8) | 0.46% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse… | |
| Modificada | Alta (7.8) | 0.43% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault… | |
| Modificada | Alta (7.8) | 0.43% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a… | |
| Modificada | Alta (7.8) | 0.45% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be… | |
| Modificada | Alta (7.8) | 0.50% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite. | |
| Modificada | Alta (7.8) | 0.50% | — | GstreamerDebian Linux | 19/7/2022 | 17/6/2026 | Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (7.8) | 0.30% | — | Splashtop Streamer | 15/2/2022 | 17/6/2026 | Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | |
| Modificada | Media (5.5) | 5.4% | — | GstreamerNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+8 | 2/6/2021 | 17/6/2026 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. | |
| Modificada | Alta (7.8) | 1.8% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. | |
| Modificada | Alta (7.8) | 1.2% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files. | |
| Modificada | Media (6.6) | 0.55% | — | Splashtop Software UpdaterSplashtop Streamer | 21/5/2020 | 17/6/2026 | A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking.… | |
| Modificada | Alta (7.5) | 2.9% | — | Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Media (6.5) | 27% | 💥 Exploit | Softvelum Nimble Streamer | 22/8/2019 | 17/6/2026 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server. | |
| Modificada | Alta (7.8) | 0.41% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all… | |
| Modificada | Crítica (9.8) | 2.0% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's… | |
| Modificada | Alta (8.8) | 1.8% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is… | |
| Modificada | Media (6.1) | 0.82% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to… | |
| Modificada | Alta (8.8) | 5.9% | — | GstreamerDebian LinuxCanonical Ubuntu Linux | 24/4/2019 | 17/6/2026 | GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution. | |
| Modificada | Media (5.9) | 0.91% | — | Subsonic Music Streamer | 11/9/2018 | 17/6/2026 | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data. | |
| Modificada | Alta (7.5) | 4.4% | — | GstreamerDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 9/2/2017 | 17/6/2026 | The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing. | |
| Modificada | Alta (7.5) | 3.6% | — | GstreamerDebian Linux | 9/2/2017 | 17/6/2026 | The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors. | |
| Modificada | Media (5.5) | 2.0% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file. |