Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus… | |
| Modificada | Crítica (9.4) | 1.5% | — | Elementsproject C-lightning | 4/10/2021 | 17/6/2026 | Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Premiere Elements | 27/9/2021 | 17/6/2026 | Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Premiere Elements | 27/9/2021 | 17/6/2026 | Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Premiere Elements | 27/9/2021 | 17/6/2026 | Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious m4a file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Premiere Elements | 27/9/2021 | 17/6/2026 | Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.9% | — | Adobe Photoshop Elements | 27/9/2021 | 17/6/2026 | Photoshop Elements versions 2021 build 19.0 (20210304.m.156367) (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious TTF file. | |
| Modificada | Alta (7.8) | 1.8% | — | Adobe Premiere Elements | 27/9/2021 | 17/6/2026 | Adobe Premiere Elements version 2021.2235820 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious png file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Media (5.5) | 0.41% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Linux SecurityF-secure Elements Endpoint Protection | 7/9/2021 | 17/6/2026 | A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine. | |
| Modificada | Media (6.5) | 0.74% | — | F-secure AtlantF-secure Linux SecurityF-secure Elements Endpoint Protection | 23/8/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (5.5) | 0.53% | — | F-secure Client SecurityF-secure Linux SecurityF-secure Business SuiteF-secure Elements Endpoint Protection | 5/8/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine. | |
| Modificada | Media (5.5) | 0.48% | — | Adobe Premiere Elements | 28/6/2021 | 17/6/2026 | Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction. | |
| Modificada | Media (5.5) | 0.48% | — | Adobe Photoshop Elements | 28/6/2021 | 17/6/2026 | Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction. | |
| Modificada | Media (6.5) | 0.68% | — | F-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Endpoint ProtectionF-secure Linux Security | 21/6/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (5.4) | 0.59% | — | Webtechstreet Elementor Addon Elements | 5/5/2021 | 17/6/2026 | The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.4) | 0.63% | — | Wpmet Elements KIT Elementor Addons | 5/5/2021 | 17/6/2026 | The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (4.9) | 1.4% | — | Dynamic Content Elements Project Dynamic Content Elements | 28/4/2021 | 17/6/2026 | The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account. | |
| Modificada | Media (5.3) | 1.6% | — | Dynamic Content Elements Project Dynamic Content Elements | 3/2/2020 | 17/6/2026 | The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request. | |
| Modificada | Alta (7.5) | 1.8% | — | Elementsproject C-lightning | 31/1/2020 | 17/6/2026 | c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds." | |
| Modificada | Baja (3.5) | 0.95% | — | JO Hasenau Gridelements | 4/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 14% | 💥 Exploit | Adobe Photoshop Elements | 4/10/2011 | 16/6/2026 | Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296. | |
| Modificada | Alta (7.8) | 2.0% | 💥 Exploit | Adobe Photoshop Elements | 30/9/2009 | 16/6/2026 | Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via… | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Adobe GoliveAdobe IllustratorAdobe PhotoshopAdobe Photoshop Elements | 30/4/2007 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. | |
| Modificada | Alta (7.5) | 2.2% | — | Secure Elements C5 Enterprise Vulnerability Management | 31/5/2006 | 16/6/2026 | The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console. | |
| Modificada | Media (5) | 1.9% | — | Secure Elements Class 5 Enterprise Vulnerability Management | 31/5/2006 | 16/6/2026 | Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications. |