Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.88%—Opendesign Drawings Software Development KIT14/11/202117/6/2026
A Use After Free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context…
ModificadaAlta (7.8)0.88%—Opendesign Drawings Software Development KIT14/11/202117/6/2026
A Use After Free Vulnerability exists in the Open Design Alliance Drawings SDK before 2022.11. The specific flaw exists within the parsing of DWF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction…
ModificadaAlta (7.8)0.32%—NXP Mcuxpresso Software Development KIT25/10/202117/6/2026
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
ModificadaAlta (7.8)0.32%—NXP Mcuxpresso Software Development KIT25/10/202117/6/2026
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
ModificadaMedia (6.1)2.4%—Adobe XMP Toolkit Software Development KITDebian Linux13/10/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will…
ModificadaAlta (7.8)5.8%—Adobe XMP Toolkit Software Development KITDebian Linux4/10/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a specially-crafted .cpp file.
ModificadaMedia (5.5)2.3%—Adobe XMP Toolkit Software Development KITDebian Linux29/9/202117/6/2026
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.8)5.4%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaMedia (5.5)1.9%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaBaja (3.3)0.62%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.
ModificadaAlta (7.3)4.4%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaMedia (5.5)3.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaBaja (3.3)2.0%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.8)3.2%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaAlta (7.8)5.4%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.5%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaBaja (3.3)1.9%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.4)50%💥 PoCOpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaCrítica (9.8)88%—OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+2724/8/202117/6/2026
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the…
ModificadaAlta (8.3)2.6%—Throughtek Kalay P2P Software Development KIT17/8/202117/6/2026
ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte uniquely assigned identifier (UID). This could result in an attacker hijacking a victim's connection and forcing them into supplying credentials needed to access the victim TUTK device.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitRealtek Rtl819x Jungle Software Development KIT16/8/202117/6/2026
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these…