Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Listener-interactive Kfai Community Radio | 4/10/2014 | 17/6/2026 | The KFAI Community Radio (aka com.skyblue.pra.kfai) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Radios DEL Ecuador | 3/10/2014 | 17/6/2026 | The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Suriname Radio Project Suriname Radio | 29/9/2014 | 17/6/2026 | The Suriname Radio (aka com.wordbox.surinameRadio) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc ABC Lounge Webradio | 25/9/2014 | 17/6/2026 | The ABC Lounge Webradio (aka com.nobexinc.wls_66087017.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Wordbox Algeria Radio | 23/9/2014 | 17/6/2026 | The Algeria Radio (aka com.wordbox.algeriaRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nana Project African Radios Live | 23/9/2014 | 17/6/2026 | The African Radios Live (aka com.nana.africanradioslive) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.30% | — | Wordboxapps Afghan Radio | 23/9/2014 | 17/6/2026 | The Afghan Radio (aka com.wordbox.afghanRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (8.3) | 2.0% | — | Radiothermostat Ct50 FirmwareRadiothermostat Ct50Radiothermostat Ct80 FirmwareRadiothermostat Ct80 | 5/6/2014 | 16/6/2026 | Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors. | |
| Modificada | Alta (10) | 5.8% | — | GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+5 | 4/2/2014 | 16/6/2026 | The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary… | |
| Modificada | Alta (10) | 2.1% | — | GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+5 | 4/2/2014 | 16/6/2026 | The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors. | |
| Modificada | Alta (9.3) | 1.9% | — | Prosoft-technology Radiolinx Controlscape | 9/9/2013 | 16/6/2026 | ProSoft RadioLinx ControlScape before 6.00.040 uses a deficient PRNG algorithm and seeding strategy for passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Radiocms | 10/5/2013 | 16/6/2026 | SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Fxwebdesign COM Jradio | 1/2/2011 | 16/6/2026 | Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Fxwebdesign COM Jradio | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.3) | 1.9% | — | HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+14 | 18/10/2010 | 16/6/2026 | Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Scriptlerim Radio Isetek Scripti | 29/11/2009 | 16/6/2026 | RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc. | |
| Modificada | Alta (9.3) | 6.9% | 💥 Exploit | Otslabs Otsav DJOtslabs Otsav RadioOtslabs Otsav TV | 27/10/2009 | 16/6/2026 | Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file. | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | Pirateradio Destiny Media Player | 25/9/2009 | 16/6/2026 | Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Dream Radio AND TV Player Addon FOR Vbulletin | 23/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter. | |
| Modificada | Alta (7.8) | 2.5% | — | 3com Wireless 8760 Dual-radio | 4/3/2009 | 16/6/2026 | The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomla COM JoomradioJoomla | 10/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php. | |
| Modificada | Alta (10) | 54% | 💥 Exploit | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header. | |
| Modificada | Media (5) | 1.4% | — | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag. | |
| Modificada | Media (5) | 1.1% | — | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | AOL Radio | 14/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods. |