Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.24%—Castos Seriously Simple Podcasting27/10/202517/6/2026
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
AplazadaMedia (5.9)0.16%—Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI24/10/202517/6/2026
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files…
ModificadaMedia (5.9)0.22%—Castos Seriously Simple Podcasting22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.
AplazadaCrítica (9.3)0.47%—Grupo Castilla Epsilon RHAI20/10/202517/6/2026
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter ‘sEstadoUsr’ in ‘/epsilonnetws/WSAvisos.asmx’.
AnalizadaBaja (2.3)0.29%—Apereo Opencast8/10/202517/6/2026
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, in some situations, Opencast's editor may publish a video without notifying the user. This may lead to users accidentally publishing media not meant for publishing, and thus…
AnalizadaMedia (5.1)0.21%—Apereo Opencast8/10/202517/6/2026
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paella would include and render some user inputs (metadata like title, description, etc.) unfiltered and unmodified. The vulnerability allows attackers to inject and malicious…
AplazadaCrítica (9.8)0.94%💥 PoCPodlove Podcast PublisherAI23/9/202517/6/2026
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AplazadaMedia (6.5)0.17%—Pencidesign Penci PodcastAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Podcast penci-podcast allows DOM-Based XSS.This issue affects Penci Podcast: from n/a through <= 1.6.
AnalizadaAlta (8.8)0.83%—Creacast Creabox Manager22/9/202517/6/2026
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inject arbitrary Lua code into the configuration, which is then executed on the server. This allows full system compromise, including reverse shell execution or…
AnalizadaAlta (8.8)0.49%—Creacast Creabox Manager22/9/202517/6/2026
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows.
AnalizadaAlta (7.5)0.40%—Creacast Creabox Manager22/9/202517/6/2026
Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.
AplazadaBaja (2)0.13%—Buffalo WEB Caster V130AI3/9/202517/6/2026
Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by an attacker, the settings of the product may be unintentionally changed.
AnalizadaBaja (2.7)0.39%—Apereo Opencast29/8/202517/6/2026
Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partially allowing for attacks in very specific cases. The path is checked…
AplazadaAlta (8.7)1.1%—Spon Communications IP Network Broadcast SystemAI27/8/202517/6/2026
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory…
AplazadaMedia (4.7)0.21%—Podlove Podcast PublisherAI27/8/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Phishing.This issue affects Podlove Podcast Publisher: from n/a through <= 4.2.5.
AplazadaNinguna (0)0.18%—Bouncycastle Bouncy Castle FOR JavaAI22/8/202517/6/2026
Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
AplazadaMedia (5.9)0.16%—Legion OF THE Bouncy Castle INC Bouncy Castle FOR Java FipsAIBouncycastle Bouncy Castle FOR Java LTSAI22/8/202517/6/2026
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files…
AplazadaAlta (8.1)0.26%—UI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAIUI Unifi Connect Display Cast LiteAI21/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.10.3 and earlier) UniFi Connect Display Cast Pro (Version 1.0.89 and earlier) UniFi Connect…
AplazadaMedia (4.9)0.25%—UI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAIUI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAI+121/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and…
AplazadaAlta (7.1)0.23%—Lambertgroup Radio Player Shoutcast AND IcecastAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Radio Player Shoutcast & Icecast lbg-audio4-html5-shoutcast allows Reflected XSS.This issue affects Radio Player Shoutcast & Icecast: from n/a through <= 4.4.7.
AnalizadaMedia (6.5)0.31%—Talentneuron Hrforecast Suite19/8/202517/6/2026
In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
AplazadaBaja (1)0.15%—Bouncycastle Bouncy Castle FOR JavaAI16/8/202517/6/2026
Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA…
AplazadaMedia (6.3)0.46%—Legion OF THE Bouncy Castle INC BC Java BcpkixAILegion OF THE Bouncy Castle INC BC Java BcprovAILegion OF THE Bouncy Castle INC Bcpkix FipsAI13/8/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API modules) allows Excessive Allocation.…
AplazadaMedia (6.3)0.54%—Legion OF THE Bouncy Castle BC JavaAILegion OF THE Bouncy Castle BC FJAAI12/8/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associated with program files…
AplazadaCrítica (9.3)8.1%💥 ExploitIctbroadcastAI5/8/202517/6/2026
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.