Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.6% | — | Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization | 18/1/2021 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart). | |
| Modificada | Alta (7.8) | 2.2% | — | Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization | 18/1/2021 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart). | |
| Modificada | Alta (7.8) | 2.3% | — | Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization | 18/1/2021 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart). | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft BOT Framework Software Development KIT | 12/1/2021 | 17/6/2026 | Bot Framework SDK Information Disclosure Vulnerability | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.35% | — | AMD Vbios Flash Tool Software Development KIT | 12/11/2020 | 17/6/2026 | A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Active Management Technology Software Development KIT | 12/11/2020 | 17/6/2026 | Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 3.0% | — | Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+14 | 4/9/2020 | 17/6/2026 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. | |
| Modificada | Alta (8.8) | 0.26% | — | TI Simplelink-cc2640r2 Software Development KIT | 31/8/2020 | 17/6/2026 | The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Layer encryption setup is performed earlier. An attacker in radio range can achieve… | |
| Modificada | Media (6.5) | 1.2% | — | Silabs Bluetooth LOW Energy Software Development KIT | 20/8/2020 | 17/6/2026 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles. | |
| Modificada | Alta (8.8) | 3.2% | — | Silabs Bluetooth LOW Energy Software Development KIT | 20/8/2020 | 17/6/2026 | Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles. | |
| Modificada | Crítica (9.3) | 0.47% | — | Suse Linux Enterprise High Performance ComputingSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 7/8/2020 | 17/6/2026 | A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to… | |
| Modificada | Alta (7.5) | 1.4% | — | Dp3t-backend-software Development KIT Project Dp3t-backend-software Development KIT | 30/7/2020 | 17/6/2026 | An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by providing a JWT token with alg=none. | |
| Modificada | Alta (7.8) | 0.29% | — | Nvidia Jetpack Software Development KIT | 8/7/2020 | 17/6/2026 | NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges. | |
| Modificada | Alta (7.5) | 3.5% | — | Adobe DNG Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 3.5% | — | Adobe DNG Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 3.5% | — | Adobe DNG Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 2.8% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Baja (3.3) | 2.2% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 2.8% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 3.5% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Media (5.5) | 2.8% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.8) | 7.5% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 7.7% | — | Adobe Digital Negative Software Development KIT | 26/6/2020 | 17/6/2026 | Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. |