Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
473 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!VS4_SaveEnvFile function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!Conv_Macro_Data function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6ComFile!MakeItemGlidZahyou function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (7.6) | 0.48% | — | Couchbase Server | 30/4/2025 | 17/6/2026 | A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow. | |
| Analizada | Media (6.9) | 0.21% | — | Touchpoint Analytics Service | 18/4/2025 | 17/6/2026 | A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing software updates to mitigate this potential vulnerability. | |
| Aplazada | Media (4.8) | 0.26% | — | Ouch-org OuchAI | 1/4/2025 | 17/6/2026 | A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of the argument month leads to memory corruption. The attack needs to be approached locally. The exploit has been… | |
| Modificada | Media (5.3) | 0.31% | — | Codemenschen Gift Vouchers | 20/2/2025 | 17/6/2026 | The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.9.… | |
| Aplazada | Alta (7.3) | 0.32% | — | Perfood Couch-authAI | 10/2/2025 | 17/6/2026 | A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information | |
| Analizada | Media (6.5) | 0.34% | — | Couchbase Server | 27/1/2025 | 17/6/2026 | An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role. | |
| Modificada | Media (6.1) | 0.28% | — | Wpwebelite Woocommerce PDF Vouchers | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Wpwebelite Woocommerce PDF Vouchers | 18/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9. | |
| Analizada | Baja (3.3) | 0.15% | — | Samsung Smart Touch Call | 3/12/2024 | 17/6/2026 | Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT X1 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… |