Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.26%—WP EditorAI1/5/202617/6/2026
The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme…
AnalizadaBaja (2)0.31%—Pylixm Django-mdeditor30/4/202617/6/2026
All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file names.
AnalizadaAlta (7.8)0.17%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
AnalizadaAlta (7.1)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.
AnalizadaMedia (5.5)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
AnalizadaMedia (5.5)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
AnalizadaAlta (8.6)0.21%—Magix Music Editor Deluxe22/4/202617/6/2026
MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and…
AplazadaAlta (8.6)0.19%—Editorconfig-core-cAI18/4/202617/6/2026
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec_glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and…
AplazadaMedia (6.4)0.16%💥 PoCMobatek Mobaxterm Home EditionAI17/4/202617/6/2026
A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the exploitability is…
Pendiente de análisisMedia (6.2)0.16%—Onlyoffice DesktopeditorsAI16/4/202617/6/2026
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
AplazadaMedia (4.3)0.16%—Pluginus Bear Bulk Editor AND Products Manager ProfessionalAI8/4/202624/7/2026
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for…
AplazadaCrítica (9.6)0.20%—Mndpsingh287 Theme EditorAI8/4/202624/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
AplazadaMedia (5.3)0.66%—LTL Freight Quotes R L Carriers EditionAI8/4/202624/7/2026
The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET…
AplazadaMedia (5.3)0.29%—Enituretechnology LTL Freight Quotes Worldwide Express EditionAI7/4/202617/6/2026
Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
AplazadaMedia (5.5)0.47%—Huimeicloud HM EditorAI2/4/202624/7/2026
A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The…
AplazadaAlta (8.4)0.21%—ORA Tools PDF Reader Reader Editor APPAI1/4/202617/6/2026
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AnalizadaAlta (7.8)0.17%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files,…
AnalizadaAlta (7.8)0.22%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and…
AnalizadaAlta (7.8)0.17%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and…
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to…
AnalizadaAlta (7.8)0.19%—Foxit PDF EditorFoxit PDF Reader1/4/202617/6/2026
The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local…