Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.70% | — | Foxit PDF EditorFoxit PDF Reader | 18/1/2023 | 17/6/2026 | Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability. | |
| Modificada | Alta (7.1) | 0.57% | — | UBI Reader Project UBI Reader | 17/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extract_files of the file ubireader/ubifs/output.py of the component UBIFS File Handler. The manipulation leads to path traversal. The attack may be launched remotely.… | |
| Modificada | Alta (7.8) | 1.1% | — | Foxit PDF Reader | 21/11/2022 | 17/6/2026 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user… | |
| Modificada | Alta (7.8) | 1.2% | — | Foxit PDF Reader | 21/11/2022 | 17/6/2026 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick… | |
| Modificada | Alta (7.8) | 1.5% | 💥 PoC | Foxit PDF Reader | 21/11/2022 | 17/6/2026 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An attacker needs to trick the user into… | |
| Modificada | Alta (7.8) | 1.1% | — | Foxit PDF Reader | 21/11/2022 | 17/6/2026 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to… | |
| Modificada | Media (5.5) | 0.34% | — | Xpdfreader Xpdf | 15/11/2022 | 17/6/2026 | A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Modificada | Media (5.5) | 0.26% | — | Xpdfreader Xpdf | 14/11/2022 | 17/6/2026 | XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795. | |
| Modificada | Crítica (9.8) | 1.2% | — | Kavitareader Kavita | 14/11/2022 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. | |
| Modificada | Media (5.3) | 0.99% | — | Kavitareader Kavita | 11/11/2022 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. | |
| Modificada | Alta (7.5) | 0.75% | — | Glyphandcog Xpdfreader | 10/11/2022 | 17/6/2026 | xpdfreader 4.03 is vulnerable to Buffer Overflow. | |
| Modificada | Alta (7.8) | 1.6% | — | Foxitsoftware Foxit Reader | 9/11/2022 | 17/6/2026 | An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path. | |
| Modificada | Media (5.5) | 0.56% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user… | |
| Modificada | Alta (7.8) | 2.9% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Alta (7.8) | 2.7% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Media (5.5) | 2.2% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user… | |
| Modificada | Media (5.5) | 2.6% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user… | |
| Modificada | Media (5.5) | 4.4% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 14/10/2022 | 17/6/2026 | Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue… | |
| Modificada | Media (5.5) | 0.39% | — | Xpdfreader Xpdf | 30/9/2022 | 17/6/2026 | An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088. | |
| Modificada | Media (5.5) | 0.36% | — | Xpdfreader Xpdf | 30/9/2022 | 17/6/2026 | An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928. | |
| Modificada | Media (5.5) | 0.43% | — | Xpdfreader Xpdf | 30/9/2022 | 17/6/2026 | An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. | |
| Modificada | Alta (7.8) | 0.47% | — | Xpdfreader Xpdf | 29/9/2022 | 17/6/2026 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 0.43% | — | Xpdfreader Xpdf | 21/9/2022 | 17/6/2026 | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | |
| Modificada | Media (5.5) | 0.41% | — | Xpdfreader Xpdf | 15/9/2022 | 17/6/2026 | XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc. | |
| Modificada | Media (5.5) | 0.34% | — | Xpdfreader Xpdf | 30/8/2022 | 17/6/2026 | XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538. |