Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.56%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x5f91 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
ModificadaMedia (5.5)0.56%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x5ea2 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
ModificadaMedia (5.5)0.56%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x54dcec of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
ModificadaMedia (5.5)0.69%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x576b of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
ModificadaMedia (5.5)0.66%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x76af of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
ModificadaMedia (5.5)0.56%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in ntdll!RtlpCoalesceFreeBlocks+0x268 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
ModificadaMedia (5.5)0.73%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x3c3682 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
ModificadaMedia (5.5)0.66%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor+0x5cd7 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
ModificadaMedia (5.5)0.71%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted JPG file. Related to Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at JPGCodec+0x753648.
ModificadaMedia (5.5)0.66%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV starting at Editor!TMethodImplementationIntercept+0x4189c6 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted ico file.
ModificadaMedia (5.5)0.73%—Wildbit-soft Wildbit Viewer10/11/202117/6/2026
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x53f6c3 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted psd file.
ModificadaAlta (7.8)6.8%—Microsoft 3D Viewer10/11/202119/8/2026
3D Viewer Remote Code Execution Vulnerability
ModificadaAlta (7.8)4.3%—Microsoft 3D Viewer10/11/202119/8/2026
3D Viewer Remote Code Execution Vulnerability
AnalizadaCrítica (9.8)7.2%💥 PoCJanobe Online Reviewer System29/10/202117/6/2026
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
ModificadaAlta (7.8)0.81%—Helpuviewer27/10/202117/6/2026
An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator.
ModificadaAlta (8.8)8.9%—Teamviewer25/10/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue…
ModificadaMedia (5.4)0.65%—PDF Viewer Block FOR Gutenberg Project PDF Viewer Block FOR Gutenberg18/10/202117/6/2026
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
ModificadaAlta (8.8)4.3%—Teamlead Pdf-light-viewer18/10/202117/6/2026
The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via OS Command Injection when invoking Ghostscript.
ModificadaCrítica (9.8)2.8%—Commonwl Cwlviewer1/10/202117/6/2026
cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing…
ModificadaAlta (7.8)1.3%—Scalabium Dbase Viewer1/10/202117/6/2026
Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that triggers a buffer overflow. An attacker can use the Structured Exception Handler (SEH) records and redirect execution to attacker-controlled code.
ModificadaAlta (7.8)4.2%—Adobe Svg-native-viewer27/9/202117/6/2026
Adobe svg-native-viewer 8182d14dfad5d1e10f53ed830328d7d9a3cfa96d and earlier versions are affected by a heap buffer overflow vulnerability due to insecure handling of a malicious .svg file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit…
ModificadaMedia (6.5)0.96%—Realvnc VNC Viewer17/9/202117/6/2026
RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB protocol data. NOTE: It is asserted that this issue requires social engineering a user into connecting to a fake VNC Server. The VNC Viewer application they are using will then hang, until terminated, but…
ModificadaMedia (6.1)1.1%—Pdftron Webviewer UI15/9/202117/6/2026
PDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code.
ModificadaMedia (6.5)0.76%—SAP 3D Visual Enterprise Viewer14/9/202117/6/2026
When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (8.8)0.71%—Fileviewer Project Fileviewer13/9/202117/6/2026
The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack
Orbitaley — Vulnerabilidades