Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.41%—AzuracastAILiquidsoapAI24/8/202624/9/2026
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in…
AnalizadaAlta (8.7)1.3%—Genivia Gsoap18/2/202617/6/2026
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.
ModificadaCrítica (9.3)0.65%—Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem30/12/202524/9/2026
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
AplazadaAlta (8.7)0.36%—Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI14/7/202517/6/2026
The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;…
AplazadaAlta (7.5)0.72%—Genivia GsoapAI15/1/202517/6/2026
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.
AnalizadaAlta (7.8)1.0%—Smartbear Soapui22/11/202417/6/2026
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
ModificadaCrítica (9.8)2.4%—Apache Soap14/11/202217/6/2026
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution.…
ModificadaAlta (7.5)1.9%—Apache Soap22/9/202217/6/2026
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects…
ModificadaCrítica (9.8)5.3%—Genivia GsoapOracle Communications Diameter Signaling RouterOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+225/3/202117/6/2026
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)3.0%—Genivia GsoapFedoraproject Fedora10/2/202117/6/2026
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)3.0%—Genivia GsoapFedoraproject Fedora10/2/202117/6/2026
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)5.9%—Genivia GsoapFedoraproject Fedora10/2/202117/6/2026
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)2.2%—Genivia GsoapFedoraproject Fedora10/2/202117/6/2026
A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)3.0%—Genivia GsoapFedoraproject Fedora10/2/202117/6/2026
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaMedia (4.3)0.51%—JenkinsJenkins Soapui PRO Functional Testing1/9/202017/6/2026
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
ModificadaMedia (6.5)0.63%—Jenkins Soapui PRO Functional Testing1/9/202017/6/2026
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
ModificadaAlta (7.8)4.8%—Smartbear ReadyapiSmartbear Soapui5/2/202017/6/2026
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious…
ModificadaAlta (7.8)0.34%—Soapbox Project Soapbox24/1/202016/6/2026
Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
ModificadaAlta (7.5)1.3%—Nusoap Project NusoapDebian Linux19/11/201916/6/2026
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
ModificadaAlta (7.5)14%—Genivia Gsoap21/3/201917/6/2026
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.
ModificadaAlta (8.1)2.0%—Genivia GsoapDebian Linux9/2/201917/6/2026
Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and libgsoapssl/libgsoapssl++ libraries, as these are…
ModificadaAlta (7.8)1.6%—Smartbear Soapui19/2/201817/6/2026
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
ModificadaAlta (7.5)1.8%—Libcsoap Project Libcsoap6/10/201717/6/2026
nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header.
ModificadaAlta (8.1)25%—Genivia Gsoap20/7/201717/6/2026
Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via a large XML document, aka Devil's Ivy. NOTE: the…
ModificadaAlta (7.5)1.6%—Soap\ \22/11/201617/6/2026
In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined as consisting of 10 of the previous entity, with the document consisting of a single instance of the largest entity, which expands to one billion copies of the first…