Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.97% | — | Owncast Project Owncast | 19/4/2024 | 17/6/2026 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete custom emojis, which are saved on disk. The parameter name is taken… | |
| Analizada | Crítica (9.1) | 0.41% | — | Owncast Project Owncast | 20/3/2024 | 17/6/2026 | Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit… | |
| Modificada | Crítica (9.8) | 1.6% | — | Owncast Project Owncast | 27/11/2023 | 17/6/2026 | An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function. | |
| Modificada | Media (6.5) | 1.4% | — | Owncast Project Owncast | 10/6/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. | |
| Modificada | Crítica (9.8) | 0.98% | — | Owncast Project Owncast | 29/11/2022 | 17/6/2026 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | |
| Modificada | Media (6.1) | 0.75% | — | Owncast Project Owncast | 14/12/2021 | 17/6/2026 | Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy and specifying the script-src. The worker-src is required to be… |