Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.41% | — | AzuracastAILiquidsoapAI | 24/8/2026 | 24/9/2026 | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in… | |
| Analizada | Alta (8.7) | 1.3% | — | Genivia Gsoap | 18/2/2026 | 17/6/2026 | gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences. | |
| Modificada | Crítica (9.3) | 0.65% | — | Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem | 30/12/2025 | 24/9/2026 | Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | |
| Aplazada | Alta (8.7) | 0.36% | — | Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI | 14/7/2025 | 17/6/2026 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;… | |
| Aplazada | Alta (7.5) | 0.72% | — | Genivia GsoapAI | 15/1/2025 | 17/6/2026 | In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS. | |
| Analizada | Alta (7.8) | 1.0% | — | Smartbear Soapui | 22/11/2024 | 17/6/2026 | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Modificada | Crítica (9.8) | 2.4% | — | Apache Soap | 14/11/2022 | 17/6/2026 | In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution.… | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Soap | 22/9/2022 | 17/6/2026 | An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects… | |
| Modificada | Crítica (9.8) | 5.3% | — | Genivia GsoapOracle Communications Diameter Signaling RouterOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+2 | 25/3/2021 | 17/6/2026 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 3.0% | — | Genivia GsoapFedoraproject Fedora | 10/2/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 3.0% | — | Genivia GsoapFedoraproject Fedora | 10/2/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 5.9% | — | Genivia GsoapFedoraproject Fedora | 10/2/2021 | 17/6/2026 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.2% | — | Genivia GsoapFedoraproject Fedora | 10/2/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 3.0% | — | Genivia GsoapFedoraproject Fedora | 10/2/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Media (4.3) | 0.51% | — | JenkinsJenkins Soapui PRO Functional Testing | 1/9/2020 | 17/6/2026 | Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure. | |
| Modificada | Media (6.5) | 0.63% | — | Jenkins Soapui PRO Functional Testing | 1/9/2020 | 17/6/2026 | Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Alta (7.8) | 4.8% | — | Smartbear ReadyapiSmartbear Soapui | 5/2/2020 | 17/6/2026 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious… | |
| Modificada | Alta (7.8) | 0.34% | — | Soapbox Project Soapbox | 24/1/2020 | 16/6/2026 | Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox. | |
| Modificada | Alta (7.5) | 1.3% | — | Nusoap Project NusoapDebian Linux | 19/11/2019 | 16/6/2026 | nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. | |
| Modificada | Alta (7.5) | 14% | — | Genivia Gsoap | 21/3/2019 | 17/6/2026 | Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds. | |
| Modificada | Alta (8.1) | 2.0% | — | Genivia GsoapDebian Linux | 9/2/2019 | 17/6/2026 | Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and libgsoapssl/libgsoapssl++ libraries, as these are… | |
| Modificada | Alta (7.8) | 1.6% | — | Smartbear Soapui | 19/2/2018 | 17/6/2026 | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file. | |
| Modificada | Alta (7.5) | 1.8% | — | Libcsoap Project Libcsoap | 6/10/2017 | 17/6/2026 | nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header. | |
| Modificada | Alta (8.1) | 25% | — | Genivia Gsoap | 20/7/2017 | 17/6/2026 | Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the… | |
| Modificada | Alta (7.5) | 1.6% | — | Soap\ \ | 22/11/2016 | 17/6/2026 | In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined as consisting of 10 of the previous entity, with the document consisting of a single instance of the largest entity, which expands to one billion copies of the first… |