Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.42% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.41% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.31% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.43% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current… | |
| Analizada | Alta (7.8) | 0.42% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.41% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.42% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.41% | — | Autodesk Autocad MAP 3DAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of… | |
| Analizada | Alta (7.8) | 0.44% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.41% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.42% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad MAP 3D+5 | 25/6/2024 | 17/6/2026 | A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Crítica (9.1) | 0.97% | — | Libarchive | 8/6/2024 | 17/6/2026 | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c. | |
| Aplazada | Media (5.9) | 0.44% | — | Archives Calendar WidgetAI | 14/5/2024 | 17/6/2026 | Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions. | |
| Analizada | Media (6.7) | 0.15% | — | ARM 5TH GEN GPU Architecture Kernel Driver | 3/5/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Arm 5th… | |
| Analizada | Alta (7.4) | 0.16% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 3/5/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. On Armv8.0 cores, there are certain combinations of the Linux Kernel and Mali… | |
| Analizada | Media (5.1) | 0.17% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Valhall GPU Kernel Driver | 3/5/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed… | |
| Aplazada | Baja (3.3) | 0.15% | — | Macpaw THE UnarchiverAI | 29/4/2024 | 17/6/2026 | MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items. | |
| Aplazada | Media (5.9) | 0.36% | — | Twinpictures Annual ArchiveAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annual Archive allows Stored XSS.This issue affects Annual Archive: from n/a through 1.6.0. | |
| Analizada | Media (5.9) | 0.21% | 💥 PoC | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 19/4/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel… | |
| Analizada | Media (6.8) | 0.22% | — | ARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver | 19/4/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This… | |
| Aplazada | Media (6.1) | 0.82% | 💥 PoC | Archive Tainacan CollectionAI | 16/4/2024 | 17/6/2026 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Modificada | Alta (7.5) | 0.58% | — | Searchiq | 10/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5. | |
| Analizada | Alta (7.8) | 85% | — | LibarchiveFedoraproject FedoraMicrosoft Windows 11 22h2Microsoft Windows 11 23h2+1 | 9/4/2024 | 17/6/2026 | Libarchive Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.93% | 💥 PoC | Mholt ArchiverRedhat Advanced Cluster SecurityRedhat Openshift Container Platform | 6/4/2024 | 17/6/2026 | A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library. | |
| Aplazada | Alta (7.5) | 0.46% | — | SAP SCMAISAP ScmarchiivedeventviewertoolAI | 27/3/2024 | 17/6/2026 | An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools. |