Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

3562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.70%—Foxit PDF EditorFoxit PDF Reader18/1/202317/6/2026
Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.
ModificadaAlta (7.1)0.57%—UBI Reader Project UBI Reader17/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extract_files of the file ubireader/ubifs/output.py of the component UBIFS File Handler. The manipulation leads to path traversal. The attack may be launched remotely.…
ModificadaAlta (7.8)1.1%—Foxit PDF Reader21/11/202217/6/2026
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user…
ModificadaAlta (7.8)1.2%—Foxit PDF Reader21/11/202217/6/2026
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick…
ModificadaAlta (7.8)1.5%💥 PoCFoxit PDF Reader21/11/202217/6/2026
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An attacker needs to trick the user into…
ModificadaAlta (7.8)1.1%—Foxit PDF Reader21/11/202217/6/2026
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to…
ModificadaMedia (5.5)0.34%—Xpdfreader Xpdf15/11/202217/6/2026
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
ModificadaMedia (5.5)0.26%—Xpdfreader Xpdf14/11/202217/6/2026
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
ModificadaCrítica (9.8)1.2%—Kavitareader Kavita14/11/202217/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
ModificadaMedia (5.3)0.99%—Kavitareader Kavita11/11/202217/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
ModificadaAlta (7.5)0.75%—Glyphandcog Xpdfreader10/11/202217/6/2026
xpdfreader 4.03 is vulnerable to Buffer Overflow.
ModificadaAlta (7.8)1.6%—Foxitsoftware Foxit Reader9/11/202217/6/2026
An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.
ModificadaMedia (5.5)0.56%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
ModificadaAlta (7.8)2.9%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.8)2.7%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaMedia (5.5)2.2%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
ModificadaMedia (5.5)2.6%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…
ModificadaMedia (5.5)4.4%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader14/10/202217/6/2026
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue…
ModificadaMedia (5.5)0.39%—Xpdfreader Xpdf30/9/202217/6/2026
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
ModificadaMedia (5.5)0.36%—Xpdfreader Xpdf30/9/202217/6/2026
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
ModificadaMedia (5.5)0.43%—Xpdfreader Xpdf30/9/202217/6/2026
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
ModificadaAlta (7.8)0.47%—Xpdfreader Xpdf29/9/202217/6/2026
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
ModificadaAlta (7.8)0.43%—Xpdfreader Xpdf21/9/202217/6/2026
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
ModificadaMedia (5.5)0.41%—Xpdfreader Xpdf15/9/202217/6/2026
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
ModificadaMedia (5.5)0.34%—Xpdfreader Xpdf30/8/202217/6/2026
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
Orbitaley — Vulnerabilidades