Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.8%—Santesoft Dicom Viewer PRO18/2/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K…
ModificadaAlta (7.8)1.8%—Santesoft Dicom Viewer PRO18/2/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K…
ModificadaMedia (5.5)1.5%—Santesoft Dicom Viewer PRO18/2/202217/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaMedia (6.5)1.0%—SAP 3D Visual Enterprise Viewer9/2/202217/6/2026
When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information…
ModificadaMedia (6.5)1.1%—SAP 3D Visual Enterprise Viewer9/2/202217/6/2026
When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant…
ModificadaMedia (6.5)0.89%—SAP 3D Visual Enterprise Viewer9/2/202217/6/2026
When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant…
ModificadaMedia (6.5)0.60%—Bestwebsoft Error LOG Viewer1/2/202217/6/2026
The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.
ModificadaBaja (3.3)0.89%—Teamviewer24/1/202217/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TeamViewer service. The issue…
ModificadaCrítica (9.8)1.1%—Sourcecodester Online Reviewer System Project Sourcecodester Online Reviewer System20/1/202217/6/2026
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
ModificadaMedia (5.5)1.7%—Bentley Contextcapture Viewer13/1/202217/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing…
ModificadaMedia (5.5)1.7%—Bentley Contextcapture Viewer13/1/202217/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing…
ModificadaAlta (7.8)3.8%—Teamviewer13/1/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results…
ModificadaAlta (7.8)2.5%—Bytecode Viewer Project Bytecode Viewer12/1/202217/6/2026
Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The…
ModificadaMedia (5.5)1.7%💥 PoCGoogle-protobufGoogle Protobuf-javaGoogle Protobuf-kotlinOracle Communications Cloud Native Core Console+310/1/202217/6/2026
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend…
ModificadaBaja (3.3)0.56%—SAP 3D Visual Enterprise Viewer14/12/202117/6/2026
When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application
ModificadaBaja (3.3)1.1%—SAP 3D Visual Enterprise Viewer14/12/202117/6/2026
When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application
ModificadaBaja (3.3)0.56%—SAP 3D Visual Enterprise Viewer14/12/202117/6/2026
When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)0.84%—Siemens Simcenter Star-ccm+ Viewer14/12/202117/6/2026
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < 2021.3.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this…
ModificadaMedia (5.4)0.62%—Pdf.js Viewer Project Pdf.js Viewer6/12/202117/6/2026
The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks
ModificadaAlta (7.8)0.84%—Opendesign ODA Viewer14/11/202117/6/2026
An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process
ModificadaCrítica (9.8)3.6%—Opendesign ODA Viewer14/11/202117/6/2026
An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to process invalid or malicious DWF files instead of stopping upon an exception. An attacker can leverage this vulnerability to execute code in the context of the current…
ModificadaMedia (5.5)0.62%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.
ModificadaMedia (5.5)0.73%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x5d15 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
ModificadaMedia (5.5)0.71%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address controls Code Flow starting at Editor!TMethodImplementationIntercept+0x57a3b.
Orbitaley — Vulnerabilidades