Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Rmedia SMSAI | 6/3/2026 | 17/6/2026 | Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and… | |
| Modificada | Crítica (9.8) | 0.48% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.33% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (6.1) | 0.29% | — | Conceptintermedia S@M CMS | 28/6/2024 | 17/6/2026 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | |
| Modificada | Media (4.3) | 0.28% | — | Millermedia Mandrill | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33. | |
| Modificada | Alta (8.8) | 0.69% | — | Crestron Airmedia | 23/9/2022 | 17/6/2026 | Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell. | |
| Modificada | Alta (8.8) | 1.0% | — | Crestron Airmedia | 13/9/2022 | 17/6/2026 | Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt. | |
| Modificada | Alta (7.8) | 0.37% | — | Crestron Airmedia | 13/9/2022 | 17/6/2026 | A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack. | |
| Modificada | Alta (8.8) | 1.2% | — | Crestron Airmedia | 13/9/2022 | 17/6/2026 | A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair… | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Avermedia Capture Card | 11/8/2021 | 17/6/2026 | Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.43% | — | Faulknermedia Wildlife Issues IN THE NEW Millennium | 8/10/2020 | 17/6/2026 | LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run… | |
| Modificada | Crítica (9.1) | 8.6% | — | Crestron Airmedia Am-100 Firmware | 18/1/2019 | 17/6/2026 | Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device. | |
| Modificada | Media (4.8) | 0.61% | — | Crestron Airmedia Am-100 FirmwareCrestron Airmedia Am-101 Firmware | 11/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 72% | — | Crestron Airmedia Am-100 FirmwareCrestron Airmedia Am-101 Firmware | 11/7/2018 | 17/6/2026 | Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.4% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter. | |
| Modificada | Alta (7.8) | 0.51% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user. | |
| Modificada | Crítica (9.8) | 1.7% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service. | |
| Modificada | Crítica (9.1) | 1.9% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption). | |
| Modificada | Alta (8.1) | 1.1% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext. | |
| Modificada | Alta (7.2) | 4.1% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code to the web root to gain code execution. | |
| Modificada | Alta (7.5) | 2.1% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory because a symlink exists under the web root. | |
| Modificada | Alta (8.8) | 0.64% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized actions. | |
| Modificada | Crítica (9.8) | 2.0% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication. | |
| Modificada | Alta (7.8) | 0.39% | — | Dialogic Powermedia XMS | 3/7/2018 | 17/6/2026 | Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db. | |
| Modificada | Crítica (9.8) | 18% | — | Crestron Airmedia Am-100 Firmware | 3/8/2016 | 17/6/2026 | Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter. |