Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.40% | — | File-viewer DOCAIMsdoc ViewerAI | 18/9/2026 | 24/9/2026 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | Originlab Origin ViewerAI | 15/9/2026 | 16/9/2026 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | NbviewerAI | 6/9/2026 | 10/9/2026 | nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the root as a textual prefix, disclosing… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | Moos-ivp PmarineviewerAI | 3/9/2026 | 8/9/2026 | MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish crafted NODE_REPORT data to cause memory exhaustion and stall the operator display without… | |
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Alta (7.5) | 0.27% | 💥 PoC | Teamviewer DesktopAI | 26/8/2026 | 1/9/2026 | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Pendiente de análisis | Alta (7.8) | 0.28% | — | Originlab Origin ViewerAI | 20/8/2026 | 31/8/2026 | OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.2) | 0.27% | — | PDF Smart ViewerAI | 18/8/2026 | 20/8/2026 | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | ReviewerAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | |
| Aplazada | Alta (8) | 0.40% | — | Teamviewer Full ClientAITeamviewer HostAI | 29/7/2026 | 30/7/2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | ReviewerAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | |
| Aplazada | Media (6.5) | 0.52% | — | Caxperts Universalplantviewer Webservices ServerAI | 14/7/2026 | 15/7/2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver. | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| Aplazada | Alta (7.5) | 0.60% | — | Faststone Image ViewerAI | 26/6/2026 | 26/6/2026 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file. | |
| Aplazada | Media (6.5) | 0.46% | — | Faststone Image ViewerAI | 26/6/2026 | 26/6/2026 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file. | |
| Aplazada | Alta (7.8) | 0.20% | — | Wassimulator CactusviewerAI | 3/6/2026 | 22/7/2026 | A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Goobi ViewerAIApache SolrAI | 27/5/2026 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server… | |
| Aplazada | Alta (8.7) | 0.78% | — | Pcviewer Vt1000AI | 25/5/2026 | 23/7/2026 | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files outside the… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Teamviewer DEX PlatformAI | 22/5/2026 | 23/7/2026 | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles.… | |
| Aplazada | Crítica (9.4) | 0.33% | — | Altium Enterprise Server ViewerAI | 20/5/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a… | |
| Aplazada | Media (6.1) | 0.31% | 💥 PoC | Cyntler React DOC ViewerAI | 20/5/2026 | 23/7/2026 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode | |
| Pendiente de análisis | Media (6.3) | 0.34% | — | Teamviewer DEX Platform On-premisesAI | 13/5/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution… |