Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.8) | 0.15% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution. | |
| En análisis | Alta (8.8) | 0.10% | — | Foxit PDF EditorAI | 23/9/2026 | 23/9/2026 | A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges. | |
| En análisis | Alta (7.8) | 0.13% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution. | |
| En análisis | Alta (8.8) | 0.10% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges. | |
| En análisis | Alta (7.8) | 0.21% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened. | |
| En análisis | Media (6.1) | 0.12% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials. | |
| En análisis | Alta (7.8) | 0.08% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution. | |
| En análisis | Alta (7.8) | 0.16% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution. | |
| En análisis | Alta (7.8) | 0.13% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application… | |
| En análisis | Alta (7.8) | 0.13% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application… | |
| En análisis | Alta (7.8) | 0.14% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read… | |
| En análisis | Alta (7.8) | 0.13% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF. | |
| En análisis | Alta (7.8) | 0.16% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote… | |
| En análisis | Media (4.7) | 0.10% | — | Foxit PDF EditorAIFoxit PDF ReaderAI | 23/9/2026 | 23/9/2026 | When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally. | |
| Aplazada | Crítica (9.3) | 0.58% | — | Fast Fac1203r Gigabit EditionAI | 23/9/2026 | 23/9/2026 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The… | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Aplazada | Alta (8.8) | 1.8% | — | Tuleap Enterprise EditionAI | 21/9/2026 | 21/9/2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | |
| Aplazada | Media (6.1) | 0.33% | — | Md-editor-v3AI | 18/9/2026 | 24/9/2026 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language value into class and language HTML attributes without escaping or consistently… | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI | 18/9/2026 | 18/9/2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of… | |
| Aplazada | Media (6.1) | 0.27% | — | Cutesoft Components Cute Editor FOR Asp.netAI | 17/9/2026 | 22/9/2026 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component,… | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Oracle Graalvm FOR JDKAIOracle Graalvm Enterprise EditionAIOracle GraalvmAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1; Oracle… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Business Intelligence Enterprise EditionAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… |