Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

512 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+829/1/201917/6/2026
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
ModificadaAlta (7.8)0.32%—Intel Openvino Toolkit12/9/201817/6/2026
Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access.
ModificadaMedia (6.1)1.3%—Dojotoolkit Dojo6/9/201817/6/2026
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware,…
ModificadaCrítica (9.8)2.5%—Dojotoolkit DojoDebian Linux18/8/201817/6/2026
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
ModificadaCrítica (9.8)12%💥 ExploitActivepdf Toolkit28/2/201817/6/2026
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
ModificadaMedia (6.1)1.2%—Dojotoolkit Dojo2/2/201817/6/2026
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
ModificadaMedia (5.9)1.2%—Percona ToolkitPercona Xtrabackup29/9/201717/6/2026
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional…
ModificadaAlta (8.1)2.0%—Percona Toolkit29/9/201717/6/2026
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.
ModificadaAlta (7.5)1.8%—Metadata Anonymisation Toolkit Project Metadata Anonymisation Toolkit22/5/201717/6/2026
Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual menu, which allows context-dependent attackers to obtain sensitive information by reading a file for which cleaning had been attempted.
ModificadaAlta (7.8)2.3%—Foxitsoftware Foxit PDF Toolkit7/4/201717/6/2026
Memory Corruption Vulnerability in Foxit PDF Toolkit before 2.1 allows an attacker to cause Denial of Service & Remote Code Execution when a victim opens a specially crafted PDF file.
ModificadaAlta (7.8)2.3%—Foxitsoftware Foxit PDF Toolkit13/1/201717/6/2026
Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerability has been fixed in v2.0.
ModificadaMedia (4.3)0.34%—Citrix Xenmobile MDX ToolkitCitrix Worx Home13/7/201617/6/2026
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.
ModificadaAlta (7.5)3.6%—Adobe XMP Toolkit13/7/201617/6/2026
XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
ModificadaMedia (4.3)2.2%—Dojotoolkit Dojo11/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.1)1.1%—THE Extensible Catalog Drupal Toolkit Project THE Extensible Catalog Drupal Toolkit18/8/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request.
ModificadaMedia (6.4)1.9%—Devexpress Ajax Control Toolkit18/8/201517/6/2026
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.
ModificadaMedia (5.4)0.27%—Designtoolkits Blocked IN Free20/10/201417/6/2026
The Blocked in Free (aka com.blueup.blocked) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Etoolkit Love Collage - Photo Editor9/9/201417/6/2026
The Love Collage - Photo Editor (aka com.etoolkit.lovecollage) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)1.0%—EMC RSA Bsafe ToolkitsEMC RSA Data Protection Manager17/6/201416/6/2026
The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified…
ModificadaMedia (4.9)0.88%—Nongnu Oath Toolkit9/3/201417/6/2026
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated…
ModificadaMedia (5)3.6%—3s-software Codesys Runtime Toolkit31/1/201417/6/2026
Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
ModificadaMedia (4.3)4.6%—Microsoft Enhanced Mitigation Experience Toolkit29/11/201317/6/2026
Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack.
ModificadaMedia (4.3)1.1%—Google WEB Toolkit18/11/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.97%—Linksalpha Social Sharing Toolkit Plugin1/11/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.
ModificadaMedia (6.8)10%💥 ExploitKTH Snack Sound ToolkitKTH WavesurferOpensuse28/10/201316/6/2026
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.