Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

2011 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader1/6/202317/6/2026
Story Saver para Instagram - Vídeo Downloader v1.0.6 para Android tiene un componente expuesto que proporciona un método para modificar el archivo "SharedPreference". Un atacante puede aprovechar este método para inyectar una gran cantidad de datos en cualquier archivo "SharedPreference", que se cargará en la memoria…
ModificadaCrítica (9.8)1.3%—Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader31/5/202317/6/2026
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened.…
ModificadaMedia (6.1)0.47%—VIP Video Analysis Project VIP Video Analysis31/5/202317/6/2026
A vulnerability was found in yiwent Vip Video Analysis 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/admincore.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.60%—VIP Video Analysis Project VIP Video Analysis31/5/202317/6/2026
A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file data/title.php. The manipulation of the argument titurl leads to server-side request forgery. The attack can be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.47%—Beipyvideoresolution Project Beipyvideoresolution31/5/202317/6/2026
A vulnerability, which was classified as problematic, was found in BeipyVideoResolution up to 2.6. Affected is an unknown function of the file admin/admincore.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (7.5)0.78%—Macro-video V380 PRO30/5/202317/6/2026
Macrovideo v380pro v1.4.97 shares the device id and password when sharing the device.
ModificadaAlta (7)0.35%—Getvideostream Videostream17/5/202317/6/2026
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
ModificadaAlta (7.5)0.81%—Videogo Project Videogo16/5/202317/6/2026
Incorrect access control in Videogo v6.8.1 allows attackers to access images from other devices via modification of the Device Id parameter.
ModificadaMedia (5.3)0.58%—Videogo Project Videogo16/5/202317/6/2026
Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.
ModificadaMedia (6.1)0.61%—I13websolution Video Carousel Slider With Lightbox16/5/202317/6/2026
The video carousel slider with lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (6.1)0.56%—I13websolution Video Gallery16/5/202317/6/2026
The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (6.1)0.61%—Vinteo Video Core12/5/202317/6/2026
Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.
ModificadaAlta (8.8)6.5%💥 PoCWwbn Avideo12/5/202317/6/2026
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This…
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.9)0.74%—Videolan Dav1dFedoraproject Fedora10/5/202317/6/2026
VideoLAN dav1d anterior a 1.2.0 tiene una condición de ejecución thread_task.c que puede provocar un bloqueo de la aplicación, relacionado con dav1d_decode_frame_exit.
ModificadaAlta (7.8)0.67%—Microsoft AV1 Video Extension9/5/202317/6/2026
AV1 Video Extension Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.67%—Microsoft AV1 Video Extension9/5/202317/6/2026
AV1 Video Extension Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.1%—Siemens Siveillance Video9/5/202317/6/2026
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All…
ModificadaAlta (8.8)1.1%—Siemens Siveillance Video9/5/202317/6/2026
A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All…
ModificadaMedia (5.4)0.71%—Wwbn Avideo8/5/202317/6/2026
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows attacker to insert malicious scripts.…
ModificadaAlta (7.2)3.2%💥 ExploitVideo List Manager Project Video List Manager8/5/202317/6/2026
The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaMedia (4.8)0.37%—Total-soft Video Gallery3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.
ModificadaAlta (8.8)5.2%💥 PoCWwbn Avideo28/4/202317/6/2026
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
ModificadaMedia (6.1)0.40%—Wwbn Avideo25/4/202317/6/2026
Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.
ModificadaCrítica (9.8)1.3%—Wwbn Avideo25/4/202317/6/2026
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
Orbitaley — Vulnerabilidades