Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, version 3.2.7.2. A specially crafted document can cause certain RTF tokens to dereference a pointer that has been uninitialized and then write to it. An attacker must convince a victim to open a…
ModificadaAlta (7.8)1.4%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.2.7.2. This can allow an attacker to corrupt memory, which can result in code execution under the context of the application. An attacker must convince a victim to open a specially crafted document…
ModificadaAlta (7.8)1.3%—Atlantiswordprocessor Atlantis Word Processor1/12/201817/6/2026
An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, version 3.2.7.2, while trying to null-terminate a string. A specially crafted document can allow an attacker to pass an untrusted value as a length to a constructor. This constructor will miscalculate…
ModificadaAlta (7.8)1.5%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause an uninitialized pointer representing a TTableRow to be assigned to a variable on the stack. This variable is later dereferenced and then written…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause a TTableRow instance to be referenced twice, resulting in a double-free vulnerability when both the references go out of scope. An attacker must convince a…
ModificadaAlta (7.8)0.89%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated and underflow. This length is then treated as unsigned and then used in a copying operation. Due to…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause an undersized allocation, resulting in an overflow when the application tries to copy data into it. An…
ModificadaAlta (7.8)1.4%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can cause Atlantis to skip initializing a value representing the number of columns of a table. Later, the application will use this as a length…
ModificadaAlta (7.8)1.3%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can prevent Atlas from adding elements to an array that is indexed by a loop. When reading from this array, the application will use an out-of-bounds index…
ModificadaAlta (7.8)1.0%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2.3, 3.0.2.5. A specially crafted document can cause Atlantis to write a value outside the bounds of a heap allocation, resulting in a buffer overflow. An attacker must convince a victim to open a…
ModificadaAlta (7.8)1.2%—Atlantiswordprocessor Atlantis Word Processor1/10/201817/6/2026
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution.
ModificadaAlta (7.5)0.99%—Atlant4/7/201817/6/2026
ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.
ModificadaMedia (6.1)1.6%—Code-atlantic Popup Maker2/8/201717/6/2026
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)7.5%💥 ExploitNEW Atlanta Bluedragon21/4/201517/6/2026
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.
ModificadaMedia (5.4)0.29%—Magzter Where Atlanta19/10/201417/6/2026
The Where Atlanta (aka com.magzter.whereatlanta) application 3.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (8.3)2.0%💥 ExploitCisco Scientific Atlanta Dpr/epr2320 FirmwareCisco Scientific Atlanta Dpr/epr2320Cisco Scientific Atlanta Dpr2325 FirmwareCisco Scientific Atlanta Dpr232510/12/201317/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device…
ModificadaMedia (4.3)0.94%—Cisco Scientific Atlanta Dpc/epc 3208Cisco Scientific Atlanta Dpc/epc2100Cisco Scientific Atlanta Dpc/epc2202Cisco Scientific Atlanta Dpc/epc2203+3310/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.1%—Cisco Scientific Atlanta Webstar Dpc2100r226/5/201016/6/2026
The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, which makes it easier for remote attackers to obtain privileged access.
ModificadaMedia (6.4)2.4%—Cisco Scientific Atlanta Webstar Dpc2100r226/5/201016/6/2026
The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.
ModificadaMedia (6.8)2.1%💥 ExploitCisco Scientific Atlanta Webstar Dpc2100r226/5/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change…
ModificadaBaja (2.6)1.2%—NEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX26/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.
ModificadaMedia (5)6.8%💥 ExploitNEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX26/6/200623/9/2026
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.
ModificadaMedia (4.3)1.7%💥 ExploitAtlantpro.com Atlantforum16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
ModificadaMedia (4.3)1.7%💥 ExploitAtlantpro.com Atlant PRO16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.
ModificadaAlta (7.8)2.8%💥 ExploitScientific Atlanta Dpx2100 Cable Modem16/12/200516/6/2026
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained…
Orbitaley — Vulnerabilidades