Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)1.4%—SAP 3D Visual Enterprise Viewer22/3/202117/6/2026
When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaBaja (3.3)0.61%—SAP 3D Visual Enterprise Viewer22/3/202117/6/2026
When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaBaja (3.3)0.61%—SAP 3D Visual Enterprise Viewer22/3/202117/6/2026
When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)2.7%—Faststone Image Viewer18/3/202117/6/2026
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)1.1%—Faststone Image Viewer18/3/202117/6/2026
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)1.1%—Faststone Image Viewer18/3/202117/6/2026
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)1.1%—Faststone Image Viewer18/3/202117/6/2026
FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)2.0%—Faststone Image Viewer18/3/202117/6/2026
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code…
ModificadaAlta (7.8)1.4%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.3%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.3%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.3%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.3%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.4%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.3%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (7.8)1.4%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaBaja (3.3)0.74%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaBaja (3.3)1.7%—SAP 3D Visual Enterprise Viewer9/3/202117/6/2026
When a user opens manipulated Graphics Interchange Format (.GIF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.
ModificadaAlta (8.2)13%—Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+1824/2/202117/6/2026
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
ModificadaAlta (7.8)2.9%—Luxion KeyshotLuxion Keyshot Network RenderingLuxion Keyshot ViewerLuxion Keyvr+223/2/202117/6/2026
When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are, while processing the extraction of temporary files, suffering from a directory traversal…
ModificadaAlta (7.8)2.2%—Luxion KeyshotLuxion Keyshot Network RenderingLuxion Keyshot ViewerLuxion Keyvr+223/2/202117/6/2026
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL pointer dereference issues while processing project files, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)2.6%—Luxion KeyshotLuxion Keyshot Network RenderingLuxion Keyshot ViewerLuxion Keyvr+223/2/202117/6/2026
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to multiple out-of-bounds write issues while processing project files, which may allow an attacker to execute arbitrary…
ModificadaAlta (7.8)1.6%—Luxion KeyshotLuxion Keyshot Network RenderingLuxion Keyshot ViewerLuxion Keyvr+223/2/202117/6/2026
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be pointed to a .dll from a remote network…
ModificadaAlta (7.8)2.2%—Luxion KeyshotLuxion Keyshot Network RenderingLuxion Keyshot ViewerLuxion Keyvr+223/2/202117/6/2026
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…