Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.73% | — | SAP 3D Visual Enterprise Viewer | 14/6/2022 | 17/6/2026 | When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (5.5) | 0.52% | — | SAP 3D Visual Enterprise Viewer | 14/6/2022 | 17/6/2026 | When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Alta (7.8) | 0.24% | — | Sricam Deviceviewer | 8/6/2022 | 17/6/2026 | A vulnerability was found in Sricam IP CCTV Camera. It has been classified as critical. Affected is an unknown function of the component Device Viewer. The manipulation leads to memory corruption. Local access is required to approach this attack. | |
| Modificada | Alta (7.8) | 0.31% | — | Sricam Deviceviewer | 8/6/2022 | 17/6/2026 | A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 0.85% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+25 | 19/5/2022 | 17/6/2026 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,… | |
| Modificada | Media (6.1) | 0.71% | — | Jquery Json-viewer Project Jquery Json-viewer | 4/5/2022 | 17/6/2026 | The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object, as demonstrated by a SCRIPT element. | |
| Modificada | Alta (7.8) | 1.2% | — | Graphisoft Bimx Desktop Viewer | 18/4/2022 | 17/6/2026 | An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A specially crafted file can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.1% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (6.5) | 1.1% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (6.5) | 0.99% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (6.5) | 0.89% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (6.5) | 0.99% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Media (6.5) | 0.99% | — | SAP 3D Visual Enterprise Viewer | 12/4/2022 | 17/6/2026 | When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Alta (8.6) | 15% | 💥 Exploit | Kyocera NET Viewer | 4/4/2022 | 17/6/2026 | Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function. | |
| Modificada | Media (4.2) | 0.21% | — | Teamviewer | 23/3/2022 | 17/6/2026 | TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated access to the machine would have allowed… | |
| Modificada | Media (4.9) | 5.2% | 💥 Exploit | Bestwebsoft Error LOG Viewer | 14/3/2022 | 17/6/2026 | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder | |
| Modificada | Media (5.4) | 1.1% | — | Horde Mime ViewerDebian Linux | 11/3/2022 | 17/6/2026 | lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering. | |
| Modificada | Alta (7.8) | 0.81% | — | Siemens Simcenter Star-ccm+ Viewer | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an attacker to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K… | |
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 13.2.0.21165. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2… | |
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 13.2.0.21165. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2… | |
| Modificada | Media (5.5) | 1.5% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 1.5% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM… | |
| Modificada | Alta (7.8) | 2.9% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K… |