Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

1229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisMedia (6.1)0.12%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
En análisisAlta (7.8)0.08%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
En análisisAlta (7.8)0.16%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application…
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application…
En análisisAlta (7.8)0.14%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read…
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.
En análisisAlta (7.8)0.16%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote…
En análisisMedia (4.7)0.10%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.
AplazadaMedia (5.5)0.47%—Josephchuks Php-file-manager-with-code-editorAI22/9/202622/9/2026
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out…
AplazadaMedia (6.9)0.47%—Josephchuks Php-file-manager-with-code-editorAI22/9/202622/9/2026
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about…
AplazadaMedia (6.1)0.33%—Md-editor-v3AI18/9/202624/9/2026
md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language value into class and language HTML attributes without escaping or consistently…
AplazadaMedia (6.1)0.27%—Cutesoft Components Cute Editor FOR Asp.netAI17/9/202622/9/2026
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component,…
AplazadaAlta (8.5)0.43%—BurgereditorAI10/9/20261/10/2026
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed.
AplazadaMedia (5.3)0.30%—BurgereditorAI10/9/20261/10/2026
BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product.
AplazadaMedia (6.1)0.25%—Silverpeas CoreAICkeditorAI8/9/20269/9/2026
Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.
AplazadaMedia (5.5)0.53%—Baidu UeditorAIFeehicmsAI7/9/202628/9/2026
A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is…
AplazadaMedia (5.5)0.50%—Light0011 CMSAIUeditorAI4/9/20264/9/2026
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side…
AplazadaAlta (8.5)0.58%—SuneditorAI26/8/20269/9/2026
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled raw embed HTML with DOMParser and processes the resulting DOM nodes. When an external script element follows a valid…
AplazadaAlta (8.4)1.1%—Sakura Editor Development Community Sakura EditorAI24/8/202628/8/2026
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
AnalizadaMedia (5.5)0.12%—Foxit PDF EditorFoxit PDF Reader13/8/202610/9/2026
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
AplazadaMedia (6.3)0.17%—Ministry OF Justice Uyap Document EditorAI12/8/202626/8/2026
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.
AplazadaAlta (7.1)0.25%—Wpide File Manager AND Code EditorAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
AplazadaMedia (4.3)0.19%—Themeeditor Theme EditorAI1/8/202629/9/2026
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS styles via a forged request granted they can…
AplazadaMedia (5.3)0.53%—Xdsoft Jodit EditorAI31/7/20269/9/2026
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This…