Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Tinowagner Jupyter Notebook Viewer | 5/1/2024 | 17/6/2026 | nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds. | |
| Modificada | Media (6.1) | 0.38% | — | Pexlechris Library Viewer | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer: from n/a through 2.0.6. | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Afichet Openexr Viewer | 11/12/2023 | 17/6/2026 | OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1. | |
| Modificada | Crítica (9.8) | 1.3% | 💥 PoC | Horsicq Xmachoviewer | 28/11/2023 | 17/6/2026 | A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data. | |
| Modificada | Media (4.8) | 0.39% | — | Marcomilesi Anac XML Viewer | 16/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions. | |
| Modificada | Alta (7.8) | 0.20% | — | Santesoft Dicom Viewer PRO | 19/10/2023 | 17/6/2026 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.21% | — | Santesoft Dicom Viewer PRO | 19/10/2023 | 17/6/2026 | Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.19% | — | Keyence KV Replay ViewerKeyence KV Studio | 11/10/2023 | 17/6/2026 | Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file. | |
| Modificada | Alta (7.8) | 0.68% | — | Microsoft 3D Viewer | 12/9/2023 | 17/6/2026 | 3D Viewer Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.68% | — | Microsoft 3D Viewer | 12/9/2023 | 17/6/2026 | 3D Viewer Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.68% | — | Microsoft 3D Viewer | 12/9/2023 | 17/6/2026 | 3D Viewer Remote Code Execution Vulnerability | |
| Modificada | Media (5.4) | 0.38% | — | Pexlechris Library Viewer | 4/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Pexle Chris Library Viewer plugin <= 2.0.6 versions. | |
| Modificada | Alta (7.7) | 0.46% | — | Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+5 | 15/6/2023 | 17/6/2026 | Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request. | |
| Modificada | Media (5.5) | 0.25% | — | Teamviewer Remote | 14/6/2023 | 17/6/2026 | An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration. | |
| Modificada | Alta (8.8) | 0.44% | — | Inline Google Spreadsheet Viewer Project Inline Google Spreadsheet Viewer | 31/5/2023 | 17/6/2026 | A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely.… | |
| Modificada | Media (6.1) | 0.92% | — | Uthscsa Papaya Viewer | 26/5/2023 | 17/6/2026 | An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya… | |
| Analizada | Crítica (9.8) | 0.83% | — | Janobe Online Reviewer System | 9/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql… | |
| Modificada | Media (5.4) | 0.36% | — | Simple PDF Viewer Project Simple PDF Viewer | 23/4/2023 | 17/6/2026 | Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted… | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Stimulsoft DesignerStimulsoft Viewer | 27/3/2023 | 9/7/2026 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which… | |
| Modificada | Alta (7.2) | 0.73% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Media (4.8) | 0.46% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php. |