Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

1996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Longtailvideo JW PlayerAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
Pendiente de análisisAlta (8.5)0.17%—Videolan VLC Media PlayerAI29/9/202630/9/2026
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua…
Pendiente de análisisMedia (5.1)0.18%—Wwbn AvideoAI26/9/202630/9/2026
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the…
AplazadaAlta (7.5)0.26%—Star-citizen EmbedvideoAI24/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute…
AplazadaAlta (7.2)1.0%—Openeye Apex Network Video RecorderAI22/9/202626/9/2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying…
AplazadaMedia (6.2)0.16%—Openeye Apex Network Video RecorderAI22/9/202624/9/2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code…
AplazadaMedia (5.3)0.36%—Openeye Apex Network Video RecorderAI22/9/202624/9/2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to bypass local-connection-only security controls exposed on the affected non-TLS…
AplazadaMedia (6.5)0.21%—Openeye Apex Network Video RecorderAI22/9/202624/9/2026
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the account to authenticate to the password-reset workflow. The account does not provide…
AplazadaAlta (7.5)0.50%—Nuuo Network Video RecorderAI18/9/202622/9/2026
NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This…
AplazadaAlta (8.8)1.1%—Nuuo Network Video RecorderAI18/9/202622/9/2026
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
AplazadaMedia (6.9)0.42%—Wwbn AvideoAI17/9/202622/9/2026
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly from the query string, and calls User::sendVerificationLink() with no…
AplazadaAlta (8.6)0.47%—Wwbn AvideoAI17/9/202622/9/2026
AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending a parameter-less GET request to…
AplazadaCrítica (9.1)0.53%—Wwbn AvideoAI17/9/202622/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single…
AplazadaAlta (8.3)0.30%—Wwbn AvideoAI17/9/202622/9/2026
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the channel creation time can brute-force the five-digit microsecond…
AnalizadaAlta (7.8)0.07%—Qualcomm Wsa8845h FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1617/9/202622/9/2026
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
AnalizadaAlta (7.8)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2017/9/202622/9/2026
Memory corruption while processing rear sensor IOCTL calls.
AnalizadaAlta (7)0.06%—Qualcomm Wsa8845h FirmwareQualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 Firmware+3917/9/202622/9/2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
AnalizadaAlta (7.8)0.07%—Qualcomm Iqx5121 FirmwareQualcomm Iqx7181 FirmwareQualcomm Qca0000 FirmwareQualcomm Qcm5430 Firmware+2117/9/202622/9/2026
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
AplazadaMedia (5.3)0.26%—Wwbn AvideoAI16/9/202622/9/2026
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary…
AplazadaMedia (5.3)0.26%—Wwbn AvideoAI16/9/202622/9/2026
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot…
AplazadaMedia (5.3)0.26%—DatatablesAIWwbn AvideoAI16/9/202622/9/2026
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings…
AplazadaMedia (6.9)0.30%—Wwbn AvideoAI16/9/202622/9/2026
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the…
AplazadaAlta (7.1)0.18%—Wwbn AvideoAI16/9/202622/9/2026
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present…
AplazadaMedia (5.3)0.29%—Wwbn AvideoAI16/9/202622/9/2026
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily…