Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
805 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.41% | — | Anisha Online Movie Streaming | 1/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the file /admin.php. The manipulation of the argument ID leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.6) | 0.30% | — | Grandstream Gxp1628 Firmware | 29/7/2025 | 5/7/2026 | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files. | |
| Modificada | Media (6.5) | 0.30% | — | Grandstream Ucm6510 Firmware | 29/7/2025 | 5/7/2026 | An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi. | |
| Modificada | Media (6.5) | 0.27% | — | Grandstream Ucm6510 Firmware | 29/7/2025 | 5/7/2026 | Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack. | |
| Aplazada | Media (6.4) | 0.23% | — | Streamweasels Youtube IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.21% | — | Streamweasels Kick IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.23% | — | Streamweasels Twitch IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.39% | — | Social StreamsAI | 23/7/2025 | 17/6/2026 | The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their user meta information in the update_user_meta() function. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.23% | — | Live Stream BadgerAI | 19/7/2025 | 17/6/2026 | The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.8) | 0.36% | — | Gstreamer | 7/7/2025 | 17/6/2026 | GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Aplazada | Alta (8.7) | 0.85% | — | Hikvision Streaming Media Management ServerAI | 1/7/2025 | 17/6/2026 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory… | |
| Aplazada | Media (5.1) | 0.22% | — | Ricoh Streamline NXAI | 30/6/2025 | 17/6/2026 | A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the product. | |
| Aplazada | Media (4.3) | 0.15% | — | Slickstream Slick-engagementAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Slickstream Slickstream slick-engagement allows Cross Site Request Forgery.This issue affects Slickstream: from n/a through <= 2.0.3. | |
| Aplazada | Media (4.3) | 0.27% | — | Upstreamplugin UpstreamAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpStream: a Project Management Plugin for WordPress: from n/a through <= 2.1.1. | |
| Aplazada | Media (4.3) | 0.15% | — | Marcusjansen Live-sports-streamthunderAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allows Cross Site Request Forgery.This issue affects Live Sports Streamthunder: from n/a through <= 2.1. | |
| Aplazada | Media (6.4) | 0.27% | — | Streamweasels Kick IntegrationAI | 14/6/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2) | 0.12% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code. | |
| Aplazada | Crítica (9.3) | 0.88% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product. | |
| Aplazada | Media (6.9) | 0.42% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data. | |
| Analizada | Alta (8.8) | 0.85% | — | GstreamerDebian Linux | 22/5/2025 | 17/6/2026 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (7.8) | 0.13% | — | Gstreamer | 22/5/2025 | 17/6/2026 | GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Alta (8.8) | 0.18% | — | Videowhisper Live Streaming Integration | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.This issue affects Broadcast Live Video: from n/a through <= 6.2.4. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Itel Electronics IP StreamAI | 18/4/2025 | 17/6/2026 | Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges. | |
| Aplazada | Media (5.9) | 0.29% | — | Grade Review StreamAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Grade Us, Inc. Review Stream review-stream allows Stored XSS.This issue affects Review Stream: from n/a through <= 1.6.7. | |
| Aplazada | Alta (7.6) | 0.50% | — | Solwininfotech WP Social Stream DesignerAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solwininfotech WP Social Stream Designer social-stream-design allows Blind SQL Injection.This issue affects WP Social Stream Designer: from n/a through <= 1.3. |