Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2395 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)14%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)12%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)14%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)7.0%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)31%💥 ExploitAdobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)22%💥 ExploitAdobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)25%💥 ExploitAdobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)8.7%—Adobe Flash Player20/6/201717/6/2026
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability when manipulating the ActionsScript 2 XML class. Successful exploitation could lead to arbitrary code execution.
ModificadaMedia (5.5)1.2%💥 ExploitVmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have…
ModificadaAlta (8.8)0.43%—Vmware FusionVmware Fusion PROVmware Workstation PlayerVmware Workstation PRO+17/6/201717/6/2026
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion…
ModificadaAlta (8.8)0.41%—Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have…
ModificadaAlta (8.8)0.52%—Vmware Workstation PlayerVmware Workstation PROVmware EsxiVmware Fusion+17/6/201717/6/2026
VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.
ModificadaMedia (5.5)0.34%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.
ModificadaMedia (4.7)0.29%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.
ModificadaAlta (8.8)0.39%—Vmware Workstation PlayerVmware Workstation PRO7/6/201717/6/2026
VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where…
ModificadaMedia (5.5)1.7%—Realnetworks Realplayer29/5/201717/6/2026
RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file.
ModificadaAlta (7.8)2.9%—Videolan VLC Media Player29/5/201717/6/2026
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
ModificadaAlta (7.8)3.4%—Videolan VLC Media Player29/5/201717/6/2026
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
ModificadaMedia (5.5)1.5%—Videolan VLC Media Player23/5/201717/6/2026
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
ModificadaMedia (5.5)1.4%—Videolan VLC Media PlayerDebian Linux23/5/201717/6/2026
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
ModificadaAlta (7.8)8.8%💥 ExploitVideolan VLC Media Player23/5/201717/6/2026
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
ModificadaMedia (5.5)1.3%—Videolan VLC Media Player23/5/201717/6/2026
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
ModificadaMedia (6.5)5.0%💥 ExploitVmware Workstation PlayerVmware Workstation PRO22/5/201717/6/2026
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
ModificadaAlta (7.8)5.4%💥 ExploitVmware Workstation PlayerVmware Workstation PRO22/5/201717/6/2026
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
ModificadaAlta (8.8)5.0%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19/5/201717/6/2026
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation could lead to arbitrary code execution.