Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.92%—Fujielectric V-serverFujielectric V-simulator20/12/202117/6/2026
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash.
ModificadaAlta (7.8)1.2%—Fujielectric V-server19/2/202117/6/2026
The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.8)1.2%—Fujielectric V-serverFujielectric V-simulator27/1/202117/6/2026
Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
ModificadaAlta (7.8)1.2%—Fujielectric V-serverFujielectric V-simulator27/1/202117/6/2026
Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
ModificadaAlta (7.8)2.1%—Fujielectric V-serverFujielectric V-simulator27/1/202117/6/2026
A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
ModificadaAlta (7.8)1.9%—Fujielectric V-serverFujielectric V-simulator27/1/202117/6/2026
An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
ModificadaAlta (7.8)2.1%—Fujielectric V-serverFujielectric V-simulator27/1/202117/6/2026
Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
ModificadaAlta (7.5)1.8%—Rollup-plugin-dev-server Project Rollup-plugin-dev-server25/7/202017/6/2026
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
ModificadaAlta (7.8)0.80%—Fujielectric V-server13/4/202017/6/2026
Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small.
ModificadaCrítica (9.8)14%—Fujielectric V-server13/11/201917/6/2026
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.
ModificadaCrítica (9.8)1.6%—Fujielectric V-server12/6/201917/6/2026
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.
ModificadaAlta (7.5)2.3%—Fujielectric V-server12/6/201917/6/2026
Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. An unauthenticated, remote attacker can crash vserver.exe due to an integer overflow in the UDP message handling logic.
ModificadaCrítica (9.8)3.9%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.
ModificadaCrítica (9.8)3.6%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution.
ModificadaCrítica (9.8)3.6%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.
ModificadaCrítica (9.8)3.6%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution.
ModificadaCrítica (9.8)3.9%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.
ModificadaCrítica (9.8)3.6%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code execution.
ModificadaCrítica (9.8)2.7%—Fujielectric V-server Firmware26/9/201817/6/2026
Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote code execution.
ModificadaAlta (7.5)2.6%—Webpack.js Webpack-dev-server21/9/201817/6/2026
An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a…
ModificadaAlta (7.8)1.8%—Fujielectric V-server13/9/201817/6/2026
A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code that affects Fuji Electric V-Server Lite 4.0.3.0 and prior.
ModificadaCrítica (9.8)3.8%—Fujielectric V-server VPR Firmware5/2/201817/6/2026
A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.
ModificadaAlta (7.3)2.0%—Fujielectric V-server17/7/201717/6/2026
An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior. A memory corruption vulnerability has been identified (aka improper restriction of operations within the bounds of a memory buffer), which may allow remote code execution.