Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.27% | — | Limesurvey Community EditionAI | 2/10/2026 | 2/10/2026 | An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript… | |
| Aplazada | Media (5.3) | 0.24% | — | WP Edit Password ProtectedAI | 2/10/2026 | 2/10/2026 | The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide. | |
| Aplazada | Alta (7.1) | 0.24% | — | Limesurvey Community EditionAI | 29/9/2026 | 30/9/2026 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request… | |
| Pendiente de análisis | Crítica (9.8) | 0.96% | — | Onlyoffice Document EditingAI | 25/9/2026 | 29/9/2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | |
| Aplazada | Media (5.5) | 0.42% | — | ShopxoAIBaidu UeditorAI | 24/9/2026 | 24/9/2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.26% | — | KindeditorAISem-cms SemcmsAI | 23/9/2026 | 24/9/2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Alta (7.4) | 0.39% | — | Limesurvey Community EditionAI | 23/9/2026 | 23/9/2026 | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. | |
| Pendiente de análisis | Crítica (10) | 0.39% | — | SuneditorAI | 23/9/2026 | 24/9/2026 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders… | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash. | |
| Analizada | Media (6.1) | 0.11% | — | Foxit PDF EditorFoxit PDF Reader | 23/9/2026 | 1/10/2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash. | |
| En análisis | Alta (7.8) | 0.13% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution. | |
| En análisis | Media (5.3) | 0.11% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to… | |
| En análisis | Alta (8.8) | 0.09% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges. | |
| En análisis | Alta (7.9) | 0.08% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash. | |
| En análisis | Media (6.1) | 0.11% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash. | |
| En análisis | Media (6.1) | 0.11% | — | Foxit PDF Editor ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash. | |
| En análisis | Media (6.1) | 0.11% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image parsing may cause an arithmetic underflow, resulting in an out-of-bounds read and application crash. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes. | |
| En análisis | Alta (8.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges. | |
| En análisis | Alta (7.8) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s WebP image decoding due to improper handling of bitmap stride and target buffer formats. Successful exploitation could result in an application crash. |