Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.36% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files.… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Media (5.5) | 0.36% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files.… | |
| Modificada | Media (5.5) | 0.36% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files.… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Alta (7.8) | 0.39% | — | Pdf-xchange Editor | 26/1/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted… | |
| Modificada | Media (5.3) | 3.6% | — | Avanquest Expert PDF UltimateAvanquest PDF Experte UltimateFoxitsoftware Foxit ReaderGonitro Nitro PRO+13 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the… | |
| Modificada | Media (6.5) | 6.3% | 💥 PoC | Pdf-xchange Editor | 11/10/2019 | 17/6/2026 | Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction. | |
| Modificada | Alta (7.5) | 1.6% | — | Pdf-xchange Editor | 1/9/2018 | 17/6/2026 | PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564. | |
| Modificada | Alta (7.8) | 2.5% | — | Tracker-software Pdf-xchange ViewerTracker-software Viewer AX SDK | 31/1/2018 | 17/6/2026 | Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (7.8) | 5.6% | 💥 Exploit | Tracker-software Pdf-xchange Viewer | 27/12/2017 | 17/6/2026 | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Alta (9.3) | 6.2% | — | Tracker-software Pdf-xchange Viewer | 2/4/2014 | 16/6/2026 | Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file. | |
| Modificada | Alta (9.3) | 6.3% | 💥 Exploit | Tracker-software Pdf-xchange | 8/10/2012 | 16/6/2026 | Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function. | |
| Modificada | Media (6.9) | 0.40% | — | Tracker-software Pdf-xchange Viewer | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in PDF-XChange Viewer 2.0 Build 54.0 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information. |