Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Bokublock BbadminviewscontrolBokublock Bbadminviewscontrol213 | 30/12/2015 | 17/6/2026 | SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.9) | 0.46% | — | Cimon CmnviewCimon Ultimateaccess | 14/3/2015 | 17/6/2026 | Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Alta (9.3) | 9.9% | 💥 Exploit | Xnview | 9/7/2014 | 16/6/2026 | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file. | |
| Modificada | Alta (9.3) | 3.5% | — | Xnview | 18/3/2014 | 16/6/2026 | Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 5.0% | — | Irfanview | 14/2/2014 | 16/6/2026 | Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file. | |
| Modificada | Alta (7.6) | 5.7% | — | Irfanview | 28/12/2013 | 17/6/2026 | Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Xnview | 9/8/2013 | 16/6/2026 | Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file. | |
| Modificada | Media (6.8) | 5.7% | — | Irfanview | 17/11/2012 | 16/6/2026 | Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image. | |
| Modificada | Media (6.8) | 6.4% | 💥 Exploit | Irfanview Flashpix Plugin | 2/11/2012 | 16/6/2026 | Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image. | |
| Modificada | Media (4.3) | 9.3% | 💥 Exploit | Irfanview | 25/10/2012 | 16/6/2026 | Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file. | |
| Modificada | Media (6.8) | 7.4% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image. | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image. | |
| Modificada | Media (6.8) | 8.3% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL. | |
| Modificada | Alta (9.3) | 7.7% | 💥 Exploit | Irfanview Plugins | 5/7/2012 | 16/6/2026 | Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file. | |
| Modificada | Alta (9.3) | 3.7% | — | Xnview | 9/5/2012 | 16/6/2026 | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684. | |
| Modificada | Alta (9.3) | 3.7% | — | Xnview | 9/5/2012 | 16/6/2026 | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Irfanview Flashpix Plugin | 18/4/2012 | 16/6/2026 | Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression. | |
| Modificada | Media (6.8) | 2.6% | — | Ivanview | 13/2/2012 | 16/6/2026 | Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Media (6.8) | 2.6% | — | Xnview | 13/2/2012 | 16/6/2026 | Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Media (6.8) | 52% | 💥 Exploit | Irfanview | 20/1/2012 | 16/6/2026 | Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Alta (10) | 65% | 💥 Exploit | HP Openview Network Node Manager | 2/11/2011 | 16/6/2026 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210. | |
| Modificada | Alta (10) | 12% | — | HP Openview Network Node Manager | 2/11/2011 | 16/6/2026 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209. | |
| Modificada | Alta (10) | 12% | — | HP Openview Network Node Manager | 2/11/2011 | 16/6/2026 | Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208. | |
| Modificada | Media (4.3) | 1.5% | — | HP Openview Performance Insight | 19/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 2.5% | — | HP Openview Performance Insight | 11/8/2011 | 16/6/2026 | Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors. |