Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

3562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (7.8)0.21%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
En análisisMedia (6.1)0.12%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
En análisisAlta (7.8)0.08%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
En análisisAlta (7.8)0.16%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application…
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application…
En análisisAlta (7.8)0.14%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read…
En análisisAlta (7.8)0.13%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.
En análisisAlta (7.8)0.16%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote…
En análisisMedia (4.7)0.10%—Foxit PDF EditorAIFoxit PDF ReaderAI23/9/202623/9/2026
When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.
Pendiente de análisisBaja (3.4)0.17%—Darkreader Dark ReaderAI22/9/202624/9/2026
Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion pipeline to request an unauthenticated icon-like bitmap from a locally running web server when the resource uses a known public-like HTTPS URL and is…
Pendiente de análisisAlta (7.5)0.61%—ExifreaderAI17/9/202630/9/2026
ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values while allocating an extent object for every nested-loop iteration. When…
Pendiente de análisisMedia (5.3)0.51%—ExifreaderAI14/9/202630/9/2026
ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without confirming…
AnalizadaMedia (5.5)0.23%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202611/9/2026
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue requires user interaction in…
AnalizadaMedia (6.3)0.24%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaAlta (8.8)0.24%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
AnalizadaMedia (6.3)0.60%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation…
AnalizadaMedia (5.5)0.30%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.34%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (5.5)0.26%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.31%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC8/9/202610/9/2026
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.