Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)40%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)7.6%—Adobe Digital Negative Software Development KIT26/6/202017/6/2026
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)3.3%💥 PoCPango Virtual Private Network Software Development KIT21/5/202017/6/2026
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
ModificadaCrítica (9.8)17%💥 PoCApache Log4netFedoraproject FedoraOracle Application Testing SuiteOracle Hospitality Opera 5+311/5/202017/6/2026
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
ModificadaAlta (7.8)1.4%—Autodesk FBX Software Development KIT17/4/202017/6/2026
A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it.
ModificadaMedia (5.5)0.77%—Autodesk FBX Software Development KIT17/4/202017/6/2026
A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.
ModificadaMedia (6.5)1.0%—Autodesk FBX Software Development KIT17/4/202017/6/2026
An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.
ModificadaAlta (8.8)2.1%—Autodesk FBX Software Development KIT17/4/202017/6/2026
A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.
ModificadaAlta (8.8)1.5%—Autodesk FBX Software Development KIT17/4/202017/6/2026
A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system running it.
ModificadaAlta (7.8)1.4%—Autodesk FBX Software Development KIT17/4/202017/6/2026
A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution on a system running it.
ModificadaMedia (5.3)0.28%—Bitdefender Antimalware Software Development KIT7/4/202017/6/2026
Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load third party code from a DLL library in the search path. This issue affects: Bitdefender High-Level Antimalware SDK for Windows versions prior to 3.0.1.204 .
ModificadaMedia (6.1)0.32%—Dart Software Development KIT26/3/202017/6/2026
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you…
ModificadaAlta (7.8)7.0%💥 ExploitImagemagickSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT17/2/202017/6/2026
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than…
ModificadaAlta (8.8)1.2%—NXP Mcuxpresso Software Development KIT12/2/202017/6/2026
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
ModificadaMedia (6.5)0.70%—TI Ble-stackTI Cc2640r2 Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in radio range to cause…
ModificadaMedia (6.5)1.8%—TI Cc2640r2 Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted packets.
ModificadaMedia (6.5)0.76%—Dialog-semiconductor Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to link layer packets with a payload length larger than expected, allowing attackers in radio range to cause a buffer overflow via a crafted packet. This affects, for example, August Smart Lock.
ModificadaMedia (5.7)0.63%—Dialog-semiconductor Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
ModificadaMedia (6.5)0.82%—NXP Mcuxpresso Software Development KIT10/2/202017/6/2026
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows…
ModificadaBaja (3.5)0.98%—QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+731/1/202017/6/2026
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
ModificadaMedia (6.5)3.6%—QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+423/1/202017/6/2026
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
ModificadaAlta (7.5)5.6%—Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+824/12/201917/6/2026
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
ModificadaMedia (5.5)0.31%—Intel Field Programmable Gate Array Software Development KIT FOR Opencl16/12/201917/6/2026
Improper conditions check in the Linux kernel driver for the Intel(R) FPGA SDK for OpenCL(TM) Pro Edition before version 19.4 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.88%—Autodesk FBX Software Development KIT3/12/201917/6/2026
Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causing it to run arbitrary code on the system.
ModificadaMedia (5.5)1.6%—Microsoft Open Enclave Software Development KIT12/11/201917/6/2026
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.