Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 18% | — | Foxit PDF EditorFoxit PDF Reader | 30/4/2024 | 17/6/2026 | A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick… | |
| Analizada | Media (5.5) | 0.18% | — | Xpdfreader Xpdf | 24/4/2024 | 17/6/2026 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers. | |
| Analizada | Media (5.5) | 0.18% | — | Xpdfreader Xpdf | 17/4/2024 | 17/6/2026 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText. | |
| Modificada | Alta (8.8) | 1.3% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.5% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox… | |
| Modificada | Alta (7.2) | 38% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Analizada | Alta (7.8) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 15/4/2024 | 17/6/2026 | In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there. | |
| Aplazada | Media (6.3) | 0.25% | — | Lenovo DevicesAISynaptics Fingerprint ReaderAIMicrosoft Windows HelloAI | 5/4/2024 | 17/6/2026 | An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication. | |
| Analizada | Alta (7.8) | 0.84% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.90% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Baja (3.3) | 0.71% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.90% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader template Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.92% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.86% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.91% | — | Foxit PDF EditorFoxit PDF Reader | 3/4/2024 | 17/6/2026 | Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Analizada | Media (5.5) | 0.29% | — | Xpdfreader Xpdf | 2/4/2024 | 17/6/2026 | In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. |