Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

3562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.76%—Foxit PDF EditorFoxit PDF Reader21/8/202417/6/2026
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (8.8)0.76%—Foxit PDF EditorFoxit PDF Reader21/8/202417/6/2026
Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaMedia (4.3)0.62%—Foxit PDF EditorFoxit PDF Reader21/8/202417/6/2026
Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open…
ModificadaBaja (2.1)0.39%—Xpdfreader Xpdf15/8/202417/6/2026
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
AnalizadaBaja (2.1)0.21%—Xpdfreader Xpdf15/8/202417/6/2026
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
AnalizadaBaja (2.1)0.22%—Xpdfreader Xpdf15/8/202417/6/2026
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
ModificadaMedia (5.5)2.0%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
AnalizadaMedia (5.5)1.5%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
AnalizadaMedia (5.5)1.5%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
ModificadaMedia (5.5)2.0%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
AnalizadaAlta (7.8)3.2%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)4.5%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)2.1%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the…
AnalizadaAlta (7)0.20%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-privilege access to the affected system and attack…
AnalizadaAlta (7.8)3.0%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)3.9%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
AnalizadaAlta (7.8)3.0%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7)3.5%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary code execution. This vulnerability arises when the timing of…
AnalizadaAlta (7.8)2.8%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat ReaderAdobe Acrobat Reader DC14/8/202417/6/2026
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaBaja (3.5)0.46%—Kavitareader KavitaAI28/6/202417/6/2026
Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.
ModificadaMedia (5.5)0.27%—Adobe Acrobat Reader13/6/202417/6/2026
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.
ModificadaAlta (7.5)0.28%—Adobe Acrobat Reader13/6/202417/6/2026
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are outside the…
AnalizadaAlta (8.2)0.46%—Foxit PDF EditorFoxit PDF Reader28/5/202417/6/2026
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.
AnalizadaAlta (7.8)6.6%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader23/5/202417/6/2026
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.…
AnalizadaAlta (7.8)5.9%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader23/5/202417/6/2026
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.