Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.21% | — | Ether Software Easy Video TO Ipod Converter | 12/4/2026 | 17/6/2026 | Easy Video to iPod Converter 1.6.20 contains a local buffer overflow vulnerability in the user registration field that allows local attackers to overwrite the structured exception handler. Attackers can input a crafted payload exceeding 996 bytes in the username field to trigger SEH overwrite and execute arbitrary… | |
| Aplazada | Media (6.5) | 0.27% | — | Moreconvert Woocommerce WishlistAI | 10/4/2026 | 17/6/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible… | |
| Analizada | Media (6.9) | 0.19% | — | River Past Ringtone Converter Project River Past Ringtone Converter | 5/4/2026 | 24/7/2026 | River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Activate dialog to… | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | Dennisre Audio ConverterAI | 26/3/2026 | 17/6/2026 | River Past Audio Converter 7.7.16 contains a local buffer overflow vulnerability in the activation code field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a large payload of repeated characters into the 'E-Mail and Activation Code' field and click… | |
| Aplazada | Media (6.9) | 0.18% | — | Myvideoconverter PROAI | 26/3/2026 | 17/6/2026 | MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration Code' field to… | |
| Analizada | Alta (8.6) | 0.21% | — | Boxoft WAV TO WMA Converter | 26/3/2026 | 17/6/2026 | Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code… | |
| Pendiente de análisis | Media (6.9) | 0.17% | — | Winavi Ipod/3gp/mp4/psp ConverterAI | 24/3/2026 | 17/6/2026 | WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an… | |
| Analizada | Media (6.9) | 0.23% | — | Direct-soft Winmpg Video Convert | 24/3/2026 | 17/6/2026 | WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service… | |
| Analizada | Media (6.2) | 0.17% | — | Xnview Nconvert | 23/3/2026 | 17/6/2026 | XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file | |
| Analizada | Media (6.2) | 0.17% | — | Xnview Nconvert | 23/3/2026 | 17/6/2026 | XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file. | |
| Aplazada | Media (6.9) | 0.13% | — | Dennisre Audio ConverterAI | 22/3/2026 | 17/6/2026 | Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interface to trigger an… | |
| Analizada | Media (6.8) | 0.19% | — | Tomabo MP4 Converter | 21/3/2026 | 17/6/2026 | Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can trigger a buffer overflow by pasting a large payload into the Name parameter when adding a preset in the Video/Audio… | |
| Aplazada | Media (6.9) | 0.12% | — | Winmpeg Ipod ConvertAI | 11/3/2026 | 17/6/2026 | WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to crash the application by supplying an oversized payload. Attackers can paste a large string of characters into the User Name and User Code field to trigger a denial of service condition. | |
| Analizada | Alta (8.4) | 0.39% | — | Alloksoft WMV TO AVI Mpeg DVD WMV Convertor | 18/2/2026 | 17/6/2026 | WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'License Name and License Code' field to trigger an application crash. | |
| Analizada | Crítica (9.3) | 0.68% | — | Alloksoft WMV TO AVI Mpeg DVD WMV Convertor | 18/2/2026 | 17/6/2026 | WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer… | |
| Aplazada | Alta (8.4) | 0.15% | — | Dennisre Audio ConverterAI | 12/2/2026 | 17/6/2026 | AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes of padding followed by register overwrite values to compromise the application… | |
| Aplazada | Media (6.7) | 0.33% | — | XnconvertAI | 12/2/2026 | 17/6/2026 | XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application crash. | |
| Aplazada | Alta (8.4) | 0.31% | — | Dennisre Audio ConverterAI | 12/2/2026 | 17/6/2026 | AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked. | |
| Aplazada | Media (4.8) | 0.24% | — | Converter FOR MediaAI | 12/2/2026 | 17/6/2026 | The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.5.1 via the PassthruLoader::load_image_source function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Alta (8.4) | 0.45% | — | Allok Video ConverterAI | 11/2/2026 | 17/6/2026 | Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious bytecode into the input field. | |
| Aplazada | Alta (8.4) | 0.45% | — | Allok RM Rmvb TO AVI Mpeg DVD ConverterAI | 11/2/2026 | 17/6/2026 | Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to trigger a buffer overflow and execute system… | |
| Aplazada | Media (6.7) | 0.45% | — | Torrent FLV ConverterAI | 11/2/2026 | 17/6/2026 | Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite techniques to potentially execute arbitrary code… | |
| Aplazada | Alta (8.4) | 0.45% | — | Torrent 3GP ConverterAI | 11/2/2026 | 17/6/2026 | Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the application's registration dialog to trigger code execution and open the calculator… | |
| Aplazada | Alta (8.4) | 0.18% | — | Socusoft Photo TO Video Converter ProfessionalAI | 30/1/2026 | 17/6/2026 | Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder' input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the output folder field to trigger a stack-based buffer overflow and… | |
| Aplazada | Alta (8.4) | 0.18% | — | Nidesoft 3GP Video ConverterAI | 28/1/2026 | 17/6/2026 | Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration parameter. Attackers can craft a malicious payload and paste it into the 'License Code' field to execute arbitrary code on the system. |