Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | Inline Google Spreadsheet ViewerAI | 2/5/2024 | 17/6/2026 | The Inline Google Spreadsheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gdoc' shortcode in all versions up to, and including, 0.13.2 due to insufficient input sanitization and output escaping on user supplied attributes such as 'chart_resolution'. This makes it possible… | |
| Aplazada | Media (4.7) | 0.33% | — | ViewerjsAI | 1/5/2024 | 17/6/2026 | An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading. | |
| Aplazada | Baja (3.5) | 0.45% | — | Apryse WebviewerAI | 30/4/2024 | 17/6/2026 | A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unknown part of the component PDF Document Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Crítica (9.8) | 0.83% | — | E-webinformationco Fs-ezviewer WEBAI | 29/4/2024 | 17/6/2026 | E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP… | |
| Aplazada | Alta (7.1) | 0.37% | — | Creativeinteractivemedia 3D Flipbook PDF Viewer PDF Embedder Real 3D FlipbookAI | 22/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin:… | |
| Modificada | Alta (7.8) | 0.30% | — | Keyence KV Replay ViewerKeyence KV StudioKeyence Vt5-wx15 FirmwareKeyence Vt5-wx12 Firmware | 15/4/2024 | 17/6/2026 | Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |
| Analizada | Alta (8.8) | 0.85% | — | Keyence KV Replay ViewerKeyence KV StudioKeyence Vt5-wx15 FirmwareKeyence Vt5-wx12 Firmware | 15/4/2024 | 17/6/2026 | Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |
| Aplazada | Media (4.3) | 0.50% | — | 360 Javascript ViewerAI | 9/4/2024 | 17/6/2026 | The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and nonce exposure on several AJAX actions in all versions up to, and including, 1.7.12. This makes it possible for authenticated attackers, with subscriber access or higher, to update… | |
| Aplazada | Alta (7.7) | 0.55% | — | Xwiki Macro-pdfviewerAI | 4/4/2024 | 17/6/2026 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF attachments using the PDF Viewer macro, just by passing the attachment URL as the value of the ``file`` parameter. Users with view rights can access restricted PDF attachments if they are shown on… | |
| Aplazada | Alta (7.8) | 0.19% | — | Sonic Dicom Media ViewerAI | 3/4/2024 | 17/6/2026 | Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. | |
| Aplazada | Media (6.5) | 0.34% | — | Maurice Spin 360 DEG AND 3D Model ViewerAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maurice Spin 360 deg and 3D Model Viewer allows Stored XSS.This issue affects Spin 360 deg and 3D Model Viewer: from n/a through 1.2.7. | |
| Modificada | Media (5.4) | 0.34% | — | Redlettuce PDF Viewer FOR Elementor | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3. | |
| Aplazada | Alta (7.5) | 0.46% | — | SAP SCMAISAP ScmarchiivedeventviewertoolAI | 27/3/2024 | 17/6/2026 | An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools. | |
| Aplazada | Alta (7.1) | 0.21% | — | Teamviewer Remote ClientAI | 26/3/2024 | 17/6/2026 | Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Abast Scan Visio Edocument Suite WEB ViewerAI | 21/3/2024 | 17/6/2026 | A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter. | |
| Modificada | Media (6.5) | 0.59% | — | Bestwebsoft Error LOG Viewer | 18/3/2024 | 17/6/2026 | The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization | |
| Modificada | Media (5.4) | 0.42% | — | Themencode TNC PDF Viewer | 13/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 2.8.0. | |
| Analizada | Alta (7.8) | 0.25% | — | Santesoft Dicom Viewer PRO | 1/3/2024 | 17/6/2026 | In Sante DICOM Viewer Pro versions 14.0.3 and prior, a user must open a malicious DICOM file, which could allow a local attacker to disclose information or execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.24% | — | Microdicom Dicom Viewer | 1/3/2024 | 17/6/2026 | MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within the application. | |
| Analizada | Alta (7.8) | 0.26% | — | Microdicom Dicom Viewer | 1/3/2024 | 17/6/2026 | MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. A user must open a malicious DCM file in order to exploit the vulnerability. | |
| Analizada | Alta (7.8) | 0.20% | — | Teamviewer Remote | 27/2/2024 | 17/6/2026 | Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account. | |
| Analizada | Media (6.7) | 0.36% | — | Hexagon Qognify VMS Client Viewer | 26/2/2024 | 17/6/2026 | A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met. | |
| Analizada | Alta (8.8) | 0.80% | — | E-web Fs-ezviewer | 15/2/2024 | 17/6/2026 | EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even leverage the dbo privilege in the… | |
| Modificada | Alta (8.8) | 0.21% | — | Wpsimpletools Basic LOG Viewer | 12/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4. | |
| Modificada | Media (6.1) | 0.31% | — | Orthanc-server Osimis WEB Viewer | 23/1/2024 | 17/6/2026 | A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser. |