Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
181 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 1.2% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Media (5.5) | 1.1% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue… | |
| Modificada | Media (5.5) | 1.1% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by an Access of Memory Location After End of Buffer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.… | |
| Modificada | Baja (3.3) | 1.2% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by a memory corruption vulnerability when parsing a WAF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | |
| Modificada | Media (5.5) | 1.1% | — | Adobe Character Animator | 16/3/2022 | 17/6/2026 | Adobe Character Animator version 4.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue… | |
| Modificada | Media (5.3) | 0.84% | — | Mahara | 10/2/2022 | 17/6/2026 | In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known. | |
| Modificada | Media (4.3) | 0.76% | — | Mahara | 9/2/2022 | 17/6/2026 | In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.) | |
| Modificada | Alta (7.8) | 0.15% | — | Charactell Formstorm | 25/1/2022 | 17/6/2026 | Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the… | |
| Modificada | Alta (7.8) | 1.2% | — | Optical Character Recognition Project Optical Character Recognition | 17/11/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in try_to_divide_boxes() in pgm2asc.c. | |
| Modificada | Media (5.5) | 1.1% | — | Optical Character Recognition Project Optical Character Recognition | 17/11/2021 | 17/6/2026 | An use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c. | |
| Modificada | Alta (7.8) | 1.2% | — | Optical Character Recognition Project Optical Character Recognition | 17/11/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in measure_pitch() in pgm2asc.c. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mahara | 3/11/2021 | 17/6/2026 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges. | |
| Modificada | Alta (7.8) | 0.99% | — | Mahara | 3/11/2021 | 17/6/2026 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection. | |
| Modificada | Alta (7.3) | 1.3% | — | Mahara | 2/11/2021 | 17/6/2026 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution | |
| Modificada | Media (5.4) | 0.62% | — | Mahara | 2/11/2021 | 17/6/2026 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element. | |
| Modificada | Baja (3.3) | 0.56% | — | Mahara | 2/11/2021 | 17/6/2026 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character. | |
| Modificada | Media (5.4) | 0.60% | — | Catalyst Mahara | 22/10/2021 | 17/6/2026 | Catalyst IT Ltd Mahara CMS v19.10.2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component groupfiles.php via the Number (Nombre) and Description (Descripción) parameters. | |
| Modificada | Alta (7.5) | 1.9% | — | Detect-character-encoding Project Detect-character-encoding | 31/8/2021 | 17/6/2026 | detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1. | |
| Modificada | Alta (7.5) | 2.1% | — | Detect-character-encoding Project Detect-character-encoding | 24/8/2021 | 17/6/2026 | detect-character-encoding is an open source character encoding inspection library. In detect-character-encoding v0.6.0 and earlier, data matching no charset causes the Node.js process to crash. The problem has been patched in [detect-character-encoding… | |
| Modificada | Baja (3.3) | 1.5% | — | Adobe Character Animator | 20/8/2021 | 17/6/2026 | Adobe Character Animator version 4.2 (and earlier) is affected by an out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires… | |
| Modificada | Alta (7.8) | 2.3% | — | Adobe Character Animator | 20/8/2021 | 17/6/2026 | Adobe Character Animator version 4.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Qantumthemes KentharadioQantumthemes Onair2 | 2/8/2021 | 17/6/2026 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery)… |