Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K… | |
| Modificada | Alta (7.8) | 1.8% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K… | |
| Modificada | Media (5.5) | 1.5% | — | Santesoft Dicom Viewer PRO | 18/2/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. | |
| Modificada | Media (6.5) | 1.0% | — | SAP 3D Visual Enterprise Viewer | 9/2/2022 | 17/6/2026 | When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information… | |
| Modificada | Media (6.5) | 1.1% | — | SAP 3D Visual Enterprise Viewer | 9/2/2022 | 17/6/2026 | When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant… | |
| Modificada | Media (6.5) | 0.89% | — | SAP 3D Visual Enterprise Viewer | 9/2/2022 | 17/6/2026 | When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant… | |
| Modificada | Media (6.5) | 0.60% | — | Bestwebsoft Error LOG Viewer | 1/2/2022 | 17/6/2026 | The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server. | |
| Modificada | Baja (3.3) | 0.89% | — | Teamviewer | 24/1/2022 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TeamViewer service. The issue… | |
| Modificada | Crítica (9.8) | 1.1% | — | Sourcecodester Online Reviewer System Project Sourcecodester Online Reviewer System | 20/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Alta (7.8) | 3.8% | — | Teamviewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results… | |
| Modificada | Alta (7.8) | 2.5% | — | Bytecode Viewer Project Bytecode Viewer | 12/1/2022 | 17/6/2026 | Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The… | |
| Modificada | Media (5.5) | 1.7% | 💥 PoC | Google-protobufGoogle Protobuf-javaGoogle Protobuf-kotlinOracle Communications Cloud Native Core Console+3 | 10/1/2022 | 17/6/2026 | An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend… | |
| Modificada | Baja (3.3) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 14/12/2021 | 17/6/2026 | When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application | |
| Modificada | Baja (3.3) | 1.1% | — | SAP 3D Visual Enterprise Viewer | 14/12/2021 | 17/6/2026 | When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application | |
| Modificada | Baja (3.3) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 14/12/2021 | 17/6/2026 | When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Alta (7.8) | 0.84% | — | Siemens Simcenter Star-ccm+ Viewer | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < 2021.3.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this… | |
| Modificada | Media (5.4) | 0.62% | — | Pdf.js Viewer Project Pdf.js Viewer | 6/12/2021 | 17/6/2026 | The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks | |
| Modificada | Alta (7.8) | 0.84% | — | Opendesign ODA Viewer | 14/11/2021 | 17/6/2026 | An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process | |
| Modificada | Crítica (9.8) | 3.6% | — | Opendesign ODA Viewer | 14/11/2021 | 17/6/2026 | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11. ODA Viewer continues to process invalid or malicious DWF files instead of stopping upon an exception. An attacker can leverage this vulnerability to execute code in the context of the current… | |
| Modificada | Media (5.5) | 0.62% | — | Wildbit-soft Wildbit Viewer | 10/11/2021 | 17/6/2026 | A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3. | |
| Modificada | Media (5.5) | 0.73% | — | Wildbit-soft Wildbit Viewer | 10/11/2021 | 17/6/2026 | A User Mode Write AV in Editor+0x5d15 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. | |
| Modificada | Media (5.5) | 0.71% | — | Wildbit-soft Wildbit Viewer | 10/11/2021 | 17/6/2026 | A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address controls Code Flow starting at Editor!TMethodImplementationIntercept+0x57a3b. |