Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.24%—Rmedia SMSAI6/3/202617/6/2026
Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and…
ModificadaCrítica (9.8)0.48%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
ModificadaMedia (6.1)0.33%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
ModificadaMedia (6.1)0.29%—Conceptintermedia S@M CMS28/6/202417/6/2026
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
ModificadaMedia (4.3)0.28%—Millermedia Mandrill12/6/202417/6/2026
Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.
ModificadaAlta (8.8)0.69%—Crestron Airmedia23/9/202217/6/2026
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.
ModificadaAlta (8.8)1.0%—Crestron Airmedia13/9/202217/6/2026
Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executable to gain a SYSTEM level command prompt.
ModificadaAlta (7.8)0.37%—Crestron Airmedia13/9/202217/6/2026
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and preform a privilege escalation attack.
ModificadaAlta (8.8)1.2%—Crestron Airmedia13/9/202217/6/2026
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair…
ModificadaAlta (7.8)0.25%—Intel Avermedia Capture Card11/8/202117/6/2026
Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.43%—Faulknermedia Wildlife Issues IN THE NEW Millennium8/10/202017/6/2026
LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable LiveCode application. If the application is using LiveCode's "shell()" function, it will attempt to search for "cmd.exe" in the folder of the current application and run…
ModificadaCrítica (9.1)8.6%—Crestron Airmedia Am-100 Firmware18/1/201917/6/2026
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.
ModificadaMedia (4.8)0.61%—Crestron Airmedia Am-100 FirmwareCrestron Airmedia Am-101 Firmware11/7/201817/6/2026
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.2)72%—Crestron Airmedia Am-100 FirmwareCrestron Airmedia Am-101 Firmware11/7/201817/6/2026
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)1.4%—Dialogic Powermedia XMS3/7/201817/6/2026
SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.
ModificadaAlta (7.8)0.51%—Dialogic Powermedia XMS3/7/201817/6/2026
Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user.
ModificadaCrítica (9.8)1.7%—Dialogic Powermedia XMS3/7/201817/6/2026
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.
ModificadaCrítica (9.1)1.9%—Dialogic Powermedia XMS3/7/201817/6/2026
XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption).
ModificadaAlta (8.1)1.1%—Dialogic Powermedia XMS3/7/201817/6/2026
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.
ModificadaAlta (7.2)4.1%—Dialogic Powermedia XMS3/7/201817/6/2026
Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code to the web root to gain code execution.
ModificadaAlta (7.5)2.1%—Dialogic Powermedia XMS3/7/201817/6/2026
Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory because a symlink exists under the web root.
ModificadaAlta (8.8)0.64%—Dialogic Powermedia XMS3/7/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized actions.
ModificadaCrítica (9.8)2.0%—Dialogic Powermedia XMS3/7/201817/6/2026
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.
ModificadaAlta (7.8)0.39%—Dialogic Powermedia XMS3/7/201817/6/2026
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.
ModificadaCrítica (9.8)18%—Crestron Airmedia Am-100 Firmware3/8/201617/6/2026
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.