Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.82%—Mastersoft Zook AgentMastersoft Zook Viewer7/9/202117/6/2026
A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitrary command.
ModificadaMedia (6.1)3.3%💥 ExploitMarmoset Viewer9/8/202117/6/2026
The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.
ModificadaMedia (5.4)0.62%—Steam Group Viewer Project Steam Group Viewer2/8/202117/6/2026
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaMedia (6.5)0.76%—SAP 3D Visual Enterprise Viewer14/7/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the application.
ModificadaMedia (6.5)0.84%—SAP 3D Visual Enterprise Viewer14/7/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailable until the user restarts the application.
ModificadaAlta (8.8)1.1%—HelpuftclientHelpuftserverHelpuserverHelpuviewer24/6/202117/6/2026
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
ModificadaAlta (7.8)0.47%—Teamviewer16/6/202117/6/2026
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)0.56%—SAP 3D Visual Enterprise Viewer9/6/202117/6/2026
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
ModificadaMedia (5.5)2.8%—Microsoft 3D Viewer8/6/202117/6/2026
3D Viewer Information Disclosure Vulnerability
ModificadaAlta (7.8)2.4%—Microsoft 3D Viewer8/6/202117/6/2026
3D Viewer Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft 3D Viewer8/6/202117/6/2026
3D Viewer Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.6%—Naver Comic Viewer28/5/202117/6/2026
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
ModificadaAlta (7.5)1.7%—Specotech WEB Viewer12/5/202117/6/2026
Speco Web Viewer through 2021-05-12 allows Directory Traversal via GET request for a URI with /.. at the beginning, as demonstrated by reading the /etc/passwd file.
AnalizadaCrítica (9.8)2.2%—Janobe Online Reviewer System14/4/202117/6/2026
Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.
ModificadaMedia (4.8)9.9%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+5613/4/20217/10/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
ModificadaAlta (7.8)0.33%—Bosch Video Management SystemBosch Video Management System Viewer25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch…
ModificadaBaja (3.3)0.72%—SAP 3D Visual Enterprise Viewer22/3/202117/6/2026
When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
Orbitaley — Vulnerabilidades