Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Baptiste Place IcalendrierAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baptiste Placé iCalendrier allows Stored XSS.This issue affects iCalendrier: from n/a through 1.80. | |
| Aplazada | Media (5.6) | 0.32% | — | Dormakaba Saflok MTAIDormakaba ConfidantAIDormakaba QuantumAIDormakaba SaffireAI+1 | 21/3/2024 | 17/6/2026 | The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function… | |
| Analizada | Alta (7.8) | 0.47% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 18/3/2024 | 17/6/2026 | A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.44% | — | Autodesk Autocad ElectricalAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.48% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.49% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process. | |
| Analizada | Alta (7.8) | 0.26% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.60% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.52% | — | Autodesk Autocad ElectricalAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the… | |
| Analizada | Alta (7.8) | 0.53% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.40% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.52% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process. | |
| Analizada | Alta (7.8) | 0.52% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current… | |
| Analizada | Alta (7.8) | 0.42% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.40% | — | Autodesk Autocad ElectricalAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.55% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.64% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.65% | — | Autodesk Autocad ElectricalAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.61% | — | Autodesk Autocad ElectricalAutodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3D+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Analizada | Alta (7.8) | 0.48% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current… | |
| Analizada | Alta (7.8) | 0.46% | — | Autodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad ElectricalAutodesk Autocad Mechanical+5 | 22/2/2024 | 17/6/2026 | A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the… | |
| Analizada | Media (4.3) | 0.46% | — | Oracle Customer Relationship Management Technical Foundation | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Admin Console). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Analizada | Media (6.7) | 0.24% | — | Canonical LXDTianocore Edk2 | 14/2/2024 | 17/6/2026 | An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. | |
| Analizada | Media (6.7) | 0.26% | — | Canonical LXDTianocore Edk2Debian Linux | 14/2/2024 | 17/6/2026 | An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. |