Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.60%—Markdown-it-decorate Project Markdown-it-decorate25/7/202217/6/2026
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
ModificadaMedia (6.5)1.2%—Codecov-python13/7/202217/6/2026
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
ModificadaMedia (5.3)1.3%—Qdecoder Project Qdecoder3/6/202217/6/2026
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
ModificadaAlta (7.2)1.4%—Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware8/12/202117/6/2026
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).
ModificadaMedia (5.5)0.55%—KdeconnectOpensuse Backports SLEOpensuse Leap7/10/202017/6/2026
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
ModificadaCrítica (9.8)2.0%—Silk-v3-decoder Project Silk-v3-decoder9/9/202017/6/2026
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.
ModificadaCrítica (9.3)3.8%—Codecov20/7/202017/6/2026
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix…
ModificadaCrítica (9.8)2.1%—Decompress Project Decompress26/4/202017/6/2026
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
ModificadaAlta (8.8)2.9%—Codecov17/2/202017/6/2026
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.
ModificadaAlta (8.8)1.9%—Codecov Nodejs Uploader25/1/202017/6/2026
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
ModificadaAlta (7.8)1.3%—Audiocoding Freeware Advanced Audio Decoder 2Debian Linux21/8/201917/6/2026
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow…
ModificadaAlta (7.5)1.4%—CAT Runner\ Decorate Home Project22/7/201917/6/2026
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
ModificadaAlta (7.1)1.2%—Audiocoding Freeware Advanced Audio Decoder 2Debian Linux25/1/201917/6/2026
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 222/12/201817/6/2026
A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE case.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 222/12/201817/6/2026
An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
ModificadaMedia (5.5)1.1%—Audiocoding Freeware Advanced Audio Decoder 2Debian Linux22/12/201817/6/2026
An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 222/12/201817/6/2026
An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 222/12/201817/6/2026
An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 222/12/201817/6/2026
A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.
ModificadaMedia (5.5)1.1%—Audiocoding Freeware Advanced Audio Decoder 2Debian Linux18/12/201817/6/2026
A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the ONLY_LONG_SEQUENCE case.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 218/12/201817/6/2026
A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the LONG_START_SEQUENCE case.
ModificadaAlta (7.8)1.3%—Audiocoding Freeware Advanced Audio Decoder 218/12/201817/6/2026
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled…
ModificadaAlta (7.8)1.3%—Audiocoding Freeware Advanced Audio Decoder 2Debian Linux18/12/201817/6/2026
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled.
ModificadaMedia (5.5)1.2%—Audiocoding Freeware Advanced Audio Decoder 218/12/201817/6/2026
A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
ModificadaAlta (7.8)1.3%—Audiocoding Freeware Advanced Audio Decoder 218/12/201817/6/2026
There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled…
Orbitaley — Vulnerabilidades