Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.43% | — | Fyyd Podcast ShortcodesAI | 21/3/2026 | 17/6/2026 | The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shortcodes in all versions up to, and including, 0.3.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as… | |
| Aplazada | Media (6.5) | 0.22% | — | Podlove Podcast PublisherAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a through <= 4.3.3. | |
| Analizada | Alta (8.6) | 0.30% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain hardcoded or otherwise insecure plaintext… | |
| Analizada | Crítica (9.2) | 0.15% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the… | |
| Analizada | Alta (8.5) | 0.17% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and persistence) via modification of a… | |
| Analizada | Alta (7.1) | 0.11% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service. | |
| Analizada | Alta (8.6) | 0.14% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from the `monitor` user to… | |
| Analizada | Alta (8.6) | 0.14% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared… | |
| Analizada | Alta (8.3) | 0.15% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root… | |
| Analizada | Alta (8.3) | 0.15% | — | Datacast Sfx2100 Firmware | 5/3/2026 | 17/6/2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root… | |
| Analizada | Crítica (9.2) | 0.16% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and susceptible to offline dictionary attacks using the rockyou.txt… | |
| Analizada | Alta (8.8) | 0.65% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential… | |
| Analizada | Alta (7.9) | 0.83% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write permissions to their home directory where… | |
| Analizada | Crítica (9.2) | 0.65% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain… | |
| Analizada | Alta (7.8) | 0.65% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can… | |
| Analizada | Crítica (10) | 1.1% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root,… | |
| Analizada | Crítica (9.3) | 3.0% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe `|` operator)… | |
| Analizada | Crítica (9.3) | 2.6% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr` parameter. An authenticated attacker can bypass… | |
| Analizada | Media (5.1) | 0.32% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101 allows a remote attacker to execute arbitrary web scripts or HTML. The vulnerability is triggered by… | |
| Analizada | Media (5.1) | 0.32% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101. The application fails to adequately sanitize user-supplied input provided via the `cat` parameter before… | |
| Analizada | Media (5.3) | 0.57% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows for XML Injection. The application reflects un-sanitized user input from the `file` parameter… | |
| Analizada | Media (5.3) | 0.82% | — | Datacast Sfx2100 Firmware | 4/3/2026 | 17/6/2026 | A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 101. An authenticated attacker can manipulate the `file` parameter to traverse directories and enumerate arbitrary files… | |
| Aplazada | Media (6.5) | 0.23% | — | Pencidesign Penci PodcastAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Podcast penci-podcast allows DOM-Based XSS.This issue affects Penci Podcast: from n/a through <= 1.7. | |
| Aplazada | Alta (7.1) | 0.30% | — | Centova CastAI | 18/2/2026 | 17/6/2026 | Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl and wget requests. | |
| Aplazada | Alta (7.1) | 0.43% | — | Centova CastAI | 12/2/2026 | 17/6/2026 | Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeatedly calling the database export API endpoint. Attackers can trigger 100% CPU load by sending multiple concurrent requests to the /api.php endpoint with crafted parameters. |