Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.82% | — | Mastersoft Zook AgentMastersoft Zook Viewer | 7/9/2021 | 17/6/2026 | A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Marmoset Viewer | 9/8/2021 | 17/6/2026 | The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue. | |
| Modificada | Media (5.4) | 0.62% | — | Steam Group Viewer Project Steam Group Viewer | 2/8/2021 | 17/6/2026 | The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (6.5) | 0.76% | — | SAP 3D Visual Enterprise Viewer | 14/7/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the application. | |
| Modificada | Media (6.5) | 0.84% | — | SAP 3D Visual Enterprise Viewer | 14/7/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailable until the user restarts the application. | |
| Modificada | Alta (8.8) | 1.1% | — | HelpuftclientHelpuftserverHelpuserverHelpuviewer | 24/6/2021 | 17/6/2026 | A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process. | |
| Modificada | Alta (7.8) | 0.47% | — | Teamviewer | 16/6/2021 | 17/6/2026 | TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 0.56% | — | SAP 3D Visual Enterprise Viewer | 9/6/2021 | 17/6/2026 | SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | |
| Modificada | Media (5.5) | 2.8% | — | Microsoft 3D Viewer | 8/6/2021 | 17/6/2026 | 3D Viewer Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 2.4% | — | Microsoft 3D Viewer | 8/6/2021 | 17/6/2026 | 3D Viewer Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft 3D Viewer | 8/6/2021 | 17/6/2026 | 3D Viewer Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.6% | — | Naver Comic Viewer | 28/5/2021 | 17/6/2026 | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | |
| Modificada | Alta (7.5) | 1.7% | — | Specotech WEB Viewer | 12/5/2021 | 17/6/2026 | Speco Web Viewer through 2021-05-12 allows Directory Traversal via GET request for a URI with /.. at the beginning, as demonstrated by reading the /etc/passwd file. | |
| Analizada | Crítica (9.8) | 2.2% | — | Janobe Online Reviewer System | 14/4/2021 | 17/6/2026 | Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload. | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 7/10/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (7.8) | 0.33% | — | Bosch Video Management SystemBosch Video Management System Viewer | 25/3/2021 | 17/6/2026 | Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch… | |
| Modificada | Baja (3.3) | 0.72% | — | SAP 3D Visual Enterprise Viewer | 22/3/2021 | 17/6/2026 | When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. |