Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.56% | — | RplayAI | 18/10/2025 | 1/10/2026 | rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication. | |
| Modificada | Media (6.5) | 0.70% | — | Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in | 30/4/2025 | 17/6/2026 | A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination. | |
| Modificada | Media (6.5) | 3.2% | — | Apple Airplay Audio Software Development KITApple Airplay Video Software Development KITApple Carplay Communication Plug-in | 30/4/2025 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination. | |
| Modificada | Alta (7.5) | 1.9% | — | Powerplay Gallery Project Powerplay Gallery | 23/5/2017 | 17/6/2026 | upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable. | |
| Modificada | Alta (7.5) | 4.8% | — | Wpslideshow Powerplay Gallery | 18/8/2015 | 17/6/2026 | Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/. | |
| Modificada | Alta (7.5) | 3.2% | — | Powerplay Gallery Project Powerplay Gallery | 18/8/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter. |