Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Listener-interactive Kfai Community Radio4/10/201417/6/2026
The KFAI Community Radio (aka com.skyblue.pra.kfai) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nobexrc Radios DEL Ecuador3/10/201417/6/2026
The RADIOS DEL ECUADOR (aka com.nobexinc.wls_87612622.rc) application 3.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Suriname Radio Project Suriname Radio29/9/201417/6/2026
The Suriname Radio (aka com.wordbox.surinameRadio) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nobexrc ABC Lounge Webradio25/9/201417/6/2026
The ABC Lounge Webradio (aka com.nobexinc.wls_66087017.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.30%—Wordbox Algeria Radio23/9/201417/6/2026
The Algeria Radio (aka com.wordbox.algeriaRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nana Project African Radios Live23/9/201417/6/2026
The African Radios Live (aka com.nana.africanradioslive) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.30%—Wordboxapps Afghan Radio23/9/201417/6/2026
The Afghan Radio (aka com.wordbox.afghanRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (8.3)2.0%—Radiothermostat Ct50 FirmwareRadiothermostat Ct50Radiothermostat Ct80 FirmwareRadiothermostat Ct805/6/201416/6/2026
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.
ModificadaAlta (10)5.8%—GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+54/2/201416/6/2026
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary…
ModificadaAlta (10)2.1%—GatehouseHarris BganHughes Network Systems 9201Hughes Network Systems 9450+54/2/201416/6/2026
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors.
ModificadaAlta (9.3)1.9%—Prosoft-technology Radiolinx Controlscape9/9/201316/6/2026
ProSoft RadioLinx ControlScape before 6.00.040 uses a deficient PRNG algorithm and seeding strategy for passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaAlta (7.5)2.2%💥 ExploitRadiocms10/5/201316/6/2026
SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.
ModificadaAlta (7.5)15%💥 ExploitFxwebdesign COM Jradio1/2/201116/6/2026
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
ModificadaAlta (7.5)1.1%—Fxwebdesign COM Jradio20/1/201116/6/2026
SQL injection vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (8.3)1.9%—HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+1418/10/201016/6/2026
Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)2.3%💥 ExploitScriptlerim Radio Isetek Scripti29/11/200916/6/2026
RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc.
ModificadaAlta (9.3)6.9%💥 ExploitOtslabs Otsav DJOtslabs Otsav RadioOtslabs Otsav TV27/10/200916/6/2026
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.
ModificadaAlta (9.3)35%💥 ExploitPirateradio Destiny Media Player25/9/200916/6/2026
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.
ModificadaMedia (4.3)1.2%💥 ExploitDream Radio AND TV Player Addon FOR Vbulletin23/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.
ModificadaAlta (7.8)2.5%—3com Wireless 8760 Dual-radio4/3/200916/6/2026
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.
ModificadaAlta (7.5)1.2%💥 ExploitJoomla COM JoomradioJoomla10/6/200816/6/2026
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.
ModificadaAlta (10)54%💥 ExploitRadio Toolbox Steamcast1/2/200816/6/2026
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.
ModificadaMedia (5)1.4%—Radio Toolbox Steamcast1/2/200816/6/2026
Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag.
ModificadaMedia (5)1.1%—Radio Toolbox Steamcast1/2/200816/6/2026
Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails.
ModificadaAlta (9.3)13%💥 ExploitAOL Radio14/11/200716/6/2026
Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods.
Orbitaley — Vulnerabilidades