Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.6%—Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization18/1/202117/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
ModificadaAlta (7.8)2.2%—Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization18/1/202117/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).
ModificadaAlta (7.8)2.3%—Opendesign Drawings Software Development KITSiemens ComosSiemens Jt2goSiemens Teamcenter Visualization18/1/202117/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
ModificadaMedia (5.5)1.1%—Microsoft BOT Framework Software Development KIT12/1/202117/6/2026
Bot Framework SDK Information Disclosure Vulnerability
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.35%—AMD Vbios Flash Tool Software Development KIT12/11/202017/6/2026
A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system.
ModificadaAlta (7.8)0.34%—Intel Active Management Technology Software Development KIT12/11/202017/6/2026
Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)3.0%—Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+144/9/202017/6/2026
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
ModificadaAlta (8.8)0.26%—TI Simplelink-cc2640r2 Software Development KIT31/8/202017/6/2026
The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Layer encryption setup is performed earlier. An attacker in radio range can achieve…
ModificadaMedia (6.5)1.2%—Silabs Bluetooth LOW Energy Software Development KIT20/8/202017/6/2026
Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air denial of service vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.
ModificadaAlta (8.8)3.2%—Silabs Bluetooth LOW Energy Software Development KIT20/8/202017/6/2026
Silicon Labs Bluetooth Low Energy SDK before 2.13.3 has a buffer overflow via packet data. This is an over-the-air remote code execution vulnerability in Bluetooth LE in EFR32 SoCs and associated modules running Bluetooth SDK, supporting Central or Observer roles.
ModificadaCrítica (9.3)0.47%—Suse Linux Enterprise High Performance ComputingSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT7/8/202017/6/2026
A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to…
ModificadaAlta (7.5)1.4%—Dp3t-backend-software Development KIT Project Dp3t-backend-software Development KIT30/7/202017/6/2026
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by providing a JWT token with alg=none.
ModificadaAlta (7.8)0.29%—Nvidia Jetpack Software Development KIT8/7/202017/6/2026
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
ModificadaAlta (7.5)3.5%—Adobe DNG Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.5)3.5%—Adobe DNG Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.5)3.5%—Adobe DNG Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (5.5)2.8%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaBaja (3.3)2.2%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (5.5)2.8%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.5)3.5%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (5.5)2.8%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.8)7.5%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)7.7%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.