Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Streamtube CoreAI | 30/11/2025 | 17/6/2026 | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers… | |
| Aplazada | Baja (2.1) | 0.25% | — | Lkinderbueno Streamity Xtream Iptv PlayerAI | 24/11/2025 | 17/6/2026 | A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading… | |
| Analizada | Crítica (9.8) | 0.75% | — | Axeltechnology Streamermax MK II Firmware | 19/11/2025 | 17/6/2026 | The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system… | |
| Analizada | Baja (2.1) | 0.90% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation of the argument FilePath results in path traversal. The attack may be initiated remotely. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.87% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such manipulation of the argument Path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2.1) | 0.50% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the argument orderField causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 0.50% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument sortField results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The… | |
| Analizada | Baja (2.1) | 0.50% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of the argument orderField leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 0.50% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation of the argument orderField can lead to sql injection. The attack may be performed from remote. The exploit has been… | |
| Analizada | Baja (2.1) | 0.50% | — | Streamax Crocus | 17/10/2025 | 17/6/2026 | A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit… | |
| Modificada | Alta (7.3) | 0.55% | — | Apache Streampark | 10/10/2025 | 17/6/2026 | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | |
| Aplazada | Baja (2.3) | 0.11% | — | Ricoh Streamline NXAI | 8/9/2025 | 30/9/2026 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s management tool. | |
| Aplazada | Media (6.4) | 0.24% | — | Streamweasels Kick IntegrationAI | 6/9/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.7) | 1.2% | — | Lemon8866 StreamvaultAI | 1/9/2025 | 17/6/2026 | StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker can modify certain system parameters, construct malicious commands, execute command injection attacks against the system, and ultimately gain server privileges. Users of… | |
| Aplazada | Alta (8.4) | 0.33% | 💥 Exploit | Mini-stream WM DownloaderAI | 30/8/2025 | 16/6/2026 | WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application fails to properly validate input length, allowing an attacker to overwrite structured exception handler (SEH) records and execute arbitrary code. Exploitation occurs locally when a… | |
| Modificada | Alta (7.6) | 0.59% | — | Apache Streampark | 22/8/2025 | 17/6/2026 | SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can… | |
| Analizada | Media (5.6) | 0.48% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash. | |
| Analizada | Media (5.5) | 0.20% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash. | |
| Analizada | Media (5.6) | 0.29% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash. | |
| Modificada | Alta (8.1) | 0.67% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure. | |
| Analizada | Media (6.6) | 0.20% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure. | |
| Analizada | Media (5.5) | 0.39% | — | Anisha Online Movie Streaming | 1/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-control.php. The manipulation of the argument ID leads to missing authorization. The attack can be launched remotely. The exploit has… |