Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.42% | — | Time4 PopcornAITime4 Popcorn Updater.exeAITime4 Popcorn Pt.upddAI | 27/8/2026 | 1/9/2026 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components | |
| Aplazada | Alta (8.5) | 0.15% | — | Popcorn TimeAI | 30/1/2026 | 17/6/2026 | Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during… | |
| Modificada | Media (5.4) | 0.56% | — | Popcorn Time Project Popcorn Time | 20/5/2022 | 17/6/2026 | Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands. | |
| Modificada | Crítica (9.8) | 1.5% | — | Cloudmedia Popcorn A-200 Firmware | 17/6/2018 | 17/6/2026 | An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can completely compromise it. | |
| Modificada | Alta (9.3) | 2.7% | — | Ultrafunk Popcorn | 15/5/2009 | 16/6/2026 | Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 3.3% | — | Ultrafunk Popcorn | 4/10/2002 | 16/6/2026 | Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t"). | |
| Modificada | Alta (7.5) | 3.9% | — | Ultrafunk Popcorn | 4/10/2002 | 16/6/2026 | Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field. | |
| Modificada | Media (5) | 1.7% | — | Ultrafunk Popcorn | 4/10/2002 | 16/6/2026 | Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037. |