Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.45% | — | Wwbn AvideoAI | 27/8/2026 | 29/8/2026 | AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal… | |
| Aplazada | Crítica (9.8) | 1.6% | — | UI Unifi Enterprise Audio Video BridgeAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. | |
| Aplazada | Alta (8.7) | 0.59% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with… | |
| Aplazada | Alta (8.7) | 0.46% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to… | |
| Aplazada | Alta (7.1) | 0.16% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamp. Attackers can create a forged… | |
| Aplazada | Media (6.9) | 0.17% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacker-controlled account when an… | |
| Aplazada | Media (5.3) | 0.14% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to… | |
| Aplazada | Media (6.9) | 0.36% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and… | |
| Aplazada | Alta (8.8) | 0.51% | — | Slider Hero With Video Background AnimationAI | 22/8/2026 | 26/8/2026 | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an… | |
| Aplazada | Media (6.4) | 0.13% | — | Ingenic T31AIWyze Video Doorbell V2AI | 19/8/2026 | 9/9/2026 | The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker with physical write access to boot media to forge modified SPL (Secondary… | |
| Aplazada | Media (6.5) | 0.22% | — | Featured Video PlusAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | |
| Aplazada | Media (6.9) | 1.2% | — | Wwbn AvideoAI | 11/8/2026 | 8/9/2026 | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service,… | |
| Aplazada | Media (5.1) | 0.35% | — | Wwbn AvideoAI | 11/8/2026 | 8/9/2026 | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Axis Signed Video FrameworkAI | 11/8/2026 | 3/9/2026 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected. | |
| Aplazada | Alta (7.5) | 1.1% | — | Mustafaakin Cast-localvideoAI | 10/8/2026 | 3/9/2026 | A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory… | |
| Aplazada | Media (5) | 0.27% | — | Plugins360 All-in-one Video GalleryAI | 10/8/2026 | 26/8/2026 | All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. | |
| Aplazada | Media (5.3) | 0.33% | — | Featured Video PlusAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | |
| Analizada | Alta (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Analizada | Media (6.7) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+48 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | |
| Aplazada | Crítica (9.8) | 3.0% | 💥 Exploit | Advanced Responsive Video EmbedderAI | 29/7/2026 | 30/7/2026 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs… |