Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+105 | 6/7/2026 | 7/7/2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | |
| Analizada | Alta (7.3) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+56 | 6/7/2026 | 29/9/2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. | |
| Analizada | Alta (8.8) | 0.36% | — | UI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition FirmwareUI Unifi Dream Machine PRO MAX FirmwareUI Unifi Dream Machine Beast Firmware+15 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device. | |
| En análisis | Media (6.1) | 0.27% | — | UI Unifi OS ServerUI Unifi Dream Machine Beast FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+26 | 2/7/2026 | 9/7/2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Dream Machine Beast FirmwareUI Enterprise Fortress Gateway FirmwareUI Unifi Dream Router FirmwareUI Unifi Dream Wall Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Media (4.4) | 0.34% | 💥 PoC | Product Video Gallery FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Media (6.4) | 0.35% | — | Foliovision FV Flowplayer Video PlayerAI | 1/7/2026 | 1/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Paid Videochat Turnkey Site PerformerAI | 29/6/2026 | 29/6/2026 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| Aplazada | Media (5.8) | 0.31% | — | Flash AND Html5 VideoAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. | |
| Aplazada | Media (5.3) | 0.26% | — | Avideo TopmenuAI | 20/6/2026 | 22/6/2026 | AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped menu item fields that execute for all site visitors, potentially… | |
| Aplazada | Media (6.9) | 0.61% | — | Wwbn AvideoAI | 20/6/2026 | 8/7/2026 | AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can submit private keys, ciphertext, and passphrases to perform server-side decryption without credentials, exposing key… | |
| Aplazada | Crítica (9.2) | 0.45% | — | Wwbn AvideoAI | 20/6/2026 | 23/6/2026 | AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename… | |
| Aplazada | Media (6.1) | 0.39% | — | Wwbn AvideoAI | 20/6/2026 | 22/6/2026 | AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata endpoints. Attackers… | |
| Aplazada | Alta (8.7) | 0.46% | — | Wwbn AvideoAI | 20/6/2026 | 22/6/2026 | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user… | |
| Aplazada | Media (5.3) | 0.53% | — | Video Conferencing With ZoomAI | 16/6/2026 | 17/6/2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the site's Zoom SDK… | |
| Aplazada | Media (6.5) | 0.22% | — | Wphowto Flowplayer Video PlayerAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Paid Videochat Turnkey SiteAI | 15/6/2026 | 17/6/2026 | Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Broadcast Live VideoAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | |
| Aplazada | Alta (7.2) | 0.42% | — | Foliovision FV Flowplayer Video PlayerAI | 9/6/2026 | 23/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |