Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.19% | — | Algonet Orcastatllm Researcher | 6/2/2026 | 17/6/2026 | OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through malicious research topic… | |
| Aplazada | Media (6.5) | 0.19% | — | Castos Seriously Simple PodcastingAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1. | |
| Analizada | Media (4.8) | 0.55% | 💥 Exploit | Podcastgenerator Podcast Generator | 28/1/2026 | 17/6/2026 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages. | |
| Analizada | Alta (7.4) | 0.17% | — | Nimbletech Ezcast PRO Dongle II Firmware | 27/1/2026 | 17/6/2026 | Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users. | |
| Analizada | Media (5.7) | 0.20% | — | Nimbletech Ezcast PRO Dongle II Firmware | 27/1/2026 | 17/6/2026 | Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory | |
| Analizada | Alta (7.6) | 0.25% | — | Nimbletech Ezcast PRO Dongle II Firmware | 27/1/2026 | 17/6/2026 | Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application | |
| Analizada | Media (6.8) | 0.16% | — | Nimbletech Ezcast PRO Dongle II Firmware | 27/1/2026 | 17/6/2026 | Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI | |
| Aplazada | Alta (7.3) | 0.21% | — | Ezcast PRO IIAI | 27/1/2026 | 17/6/2026 | Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and potential remote code execution | |
| Aplazada | Media (4.4) | 0.15% | — | Castos Seriously Simple PodcastingAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Server Side Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1. | |
| Aplazada | Media (4.3) | 0.17% | — | SimcastAI | 7/1/2026 | 17/6/2026 | The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the settingsPage function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they… | |
| Analizada | Alta (8.7) | 0.51% | — | Dbbroadcast SFT DAB 600/c Firmware | 22/12/2025 | 17/6/2026 | Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with… | |
| Analizada | Crítica (9.3) | 0.51% | — | Dbbroadcast SFT DAB 600/c Firmware | 22/12/2025 | 17/6/2026 | Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper… | |
| Analizada | Crítica (9.3) | 0.64% | — | Dbbroadcast SFT DAB 600/c Firmware | 22/12/2025 | 17/6/2026 | Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper… | |
| Analizada | Crítica (9.3) | 0.51% | — | Dbbroadcast SFT DAB 600/c Firmware | 22/12/2025 | 17/6/2026 | Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify… | |
| Modificada | Media (5.1) | 0.33% | — | Podcastgenerator Podcast Generator | 17/12/2025 | 17/6/2026 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page. | |
| Modificada | Media (5.1) | 0.33% | — | Podcastgenerator Podcast Generator | 17/12/2025 | 17/6/2026 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page. | |
| Modificada | Media (5.1) | 0.34% | — | Podcastgenerator Podcast Generator | 17/12/2025 | 17/6/2026 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php). | |
| Analizada | Media (5.1) | 0.57% | — | Podcastgenerator Podcast Generator | 16/12/2025 | 30/9/2026 | PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation. | |
| Analizada | Baja (3.7) | 0.25% | — | Azuracast | 12/12/2025 | 17/6/2026 | AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations. A user with specific internal knowledge of a station's operations… | |
| Analizada | Alta (8.7) | 0.48% | — | Dbbroadcast SFT DAB 600/c Firmware | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API by leveraging the session binding mechanism to perform critical operations on the… | |
| Analizada | Alta (7.1) | 0.40% | — | Dbbroadcast SFT DAB 600/c Firmware | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper… | |
| Modificada | Media (5.1) | 0.73% | — | Dbbroadcast SFT DAB 015/c FirmwareDbbroadcast SFT DAB 050/c FirmwareDbbroadcast SFT DAB 150/c FirmwareDbbroadcast SFT DAB 300/c Firmware+1 | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization. | |
| Analizada | Alta (8.6) | 0.88% | — | Dbbroadcast SFT DAB 015/c FirmwareDbbroadcast SFT DAB 050/c FirmwareDbbroadcast SFT DAB 150/c FirmwareDbbroadcast SFT DAB 300/c Firmware+1 | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account. | |
| Aplazada | Crítica (9.3) | 0.19% | — | Ezcast PRO IIAI | 10/12/2025 | 17/6/2026 | Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identifiers | |
| Aplazada | Crítica (9.3) | 0.18% | — | Ezcast PRO IIAI | 10/12/2025 | 17/6/2026 | Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI |