Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
ModificadaAlta (8.8)0.27%—Wpmilitary WP Radio25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Military WP Radio plugin <= 3.1.9 versions.
ModificadaMedia (4.8)0.41%—Gradio Project Gradio15/9/202317/6/2026
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.
ModificadaAlta (8.8)0.46%—Motorola Ebts Base Radio FirmwareMotorola Mbts Base Radio Firmware29/8/202317/6/2026
Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.
ModificadaAlta (8.4)0.18%—Motorola Mbts Base Radio Firmware29/8/202317/6/2026
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.
ModificadaMedia (6.1)0.38%—Netmix Radio Station23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tony Zeoli, Tony Hayes Radio Station by netmix® – Manage and play your Show Schedule in WordPress! plugin <= 2.4.0.9 versions.
ModificadaMedia (6.1)0.38%—Radioforge Radio Forge Muses Player With Skins27/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions.
ModificadaAlta (8.8)0.47%—Radio Buttons FOR Taxonomies Project Radio Buttons FOR Taxonomies1/7/202317/6/2026
The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request…
ModificadaCrítica (9.1)0.65%—Gradio Project Gradio8/6/202317/6/2026
Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not properly restrict file access to users. Additionally Gradio does not properly restrict the what URLs are proxied. These issues have been addressed in version 3.34.0. Users…
ModificadaCrítica (9.8)0.55%—Gradio Project Gradio23/2/202317/6/2026
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects…
ModificadaMedia (6.1)2.7%💥 PoCJqueryui Jquery UINetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+620/7/202217/6/2026
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input…
ModificadaAlta (8.8)1.3%—Gradio Project Gradio17/3/202217/6/2026
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionality which saves input/output data into a CSV file on the developer's…
ModificadaAlta (7.7)3.8%💥 ExploitGradio Project Gradio15/12/202117/6/2026
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio link can access any files on the host…
ModificadaMedia (4.8)0.64%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast1/11/202117/6/2026
The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks
ModificadaMedia (5.4)0.58%—Bplugins Streamcast Radio Player18/10/202117/6/2026
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaMedia (4.9)0.85%—Ericsson Operations Support System-radio AND Core Firmware14/10/202117/6/2026
In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.…
ModificadaMedia (6.1)0.60%—Ericsson Operations Support System-radio AND Core Firmware14/10/202117/6/2026
In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem is completely resolved in new Ericsson library browsing tool ELEX used in systems like Ericsson Network Manager. NOTE: This vulnerability only affects products that are…
ModificadaCrítica (9.8)57%💥 ExploitQantumthemes KentharadioQantumthemes Onair22/8/202117/6/2026
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery)…
ModificadaMedia (6.1)10%💥 ExploitMooveagency Select ALL Categories AND Taxonomies, Change Checkbox TO Radio Buttons14/5/202117/6/2026
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaCrítica (9.8)2.5%—Telestar Bobs Rock Radio FirmwareTelestar Dabman D10 FirmwareTelestar Dabman I30 Stereo FirmwareTelestar Imperial I110 Firmware+716/9/201917/6/2026
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey,…
ModificadaCrítica (9.8)4.0%—Telestar Bobs Rock Radio FirmwareTelestar Dabman D10 FirmwareTelestar Dabman I30 Stereo FirmwareTelestar Imperial I110 Firmware+811/9/201917/6/2026
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.
ModificadaAlta (7.8)0.94%—Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses17/5/201917/6/2026
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.94%—Soumu Electronic Reception AND Examination OF Application FOR Radio Licenses17/5/201917/6/2026
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.9)0.33%—Sagaradio Saga1-l8b Firmware24/10/201817/6/2026
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to reprogram it.
Orbitaley — Vulnerabilidades