Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.60% | — | Markdown-it-decorate Project Markdown-it-decorate | 25/7/2022 | 17/6/2026 | This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. | |
| Modificada | Media (6.5) | 1.2% | — | Codecov-python | 13/7/2022 | 17/6/2026 | This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method. | |
| Modificada | Media (5.3) | 1.3% | — | Qdecoder Project Qdecoder | 3/6/2022 | 17/6/2026 | qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding. | |
| Modificada | Alta (7.2) | 1.4% | — | Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware | 8/12/2021 | 17/6/2026 | A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000). | |
| Modificada | Media (5.5) | 0.55% | — | KdeconnectOpensuse Backports SLEOpensuse Leap | 7/10/2020 | 17/6/2026 | In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack. | |
| Modificada | Crítica (9.8) | 2.0% | — | Silk-v3-decoder Project Silk-v3-decoder | 9/9/2020 | 17/6/2026 | The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow. | |
| Modificada | Crítica (9.3) | 3.8% | — | Codecov | 20/7/2020 | 17/6/2026 | In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix… | |
| Modificada | Crítica (9.8) | 2.1% | — | Decompress Project Decompress | 26/4/2020 | 17/6/2026 | The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal. | |
| Modificada | Alta (8.8) | 2.9% | — | Codecov | 17/2/2020 | 17/6/2026 | codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596. | |
| Modificada | Alta (8.8) | 1.9% | — | Codecov Nodejs Uploader | 25/1/2020 | 17/6/2026 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | |
| Modificada | Alta (7.8) | 1.3% | — | Audiocoding Freeware Advanced Audio Decoder 2Debian Linux | 21/8/2019 | 17/6/2026 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow… | |
| Modificada | Alta (7.5) | 1.4% | — | CAT Runner\ Decorate Home Project | 22/7/2019 | 17/6/2026 | The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server. | |
| Modificada | Alta (7.1) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2Debian Linux | 25/1/2019 | 17/6/2026 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 22/12/2018 | 17/6/2026 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE case. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 22/12/2018 | 17/6/2026 | An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | |
| Modificada | Media (5.5) | 1.1% | — | Audiocoding Freeware Advanced Audio Decoder 2Debian Linux | 22/12/2018 | 17/6/2026 | An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 22/12/2018 | 17/6/2026 | An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 22/12/2018 | 17/6/2026 | An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 22/12/2018 | 17/6/2026 | A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash. | |
| Modificada | Media (5.5) | 1.1% | — | Audiocoding Freeware Advanced Audio Decoder 2Debian Linux | 18/12/2018 | 17/6/2026 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the ONLY_LONG_SEQUENCE case. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 18/12/2018 | 17/6/2026 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding to windowed output is mishandled in the LONG_START_SEQUENCE case. | |
| Modificada | Alta (7.8) | 1.3% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 18/12/2018 | 17/6/2026 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled… | |
| Modificada | Alta (7.8) | 1.3% | — | Audiocoding Freeware Advanced Audio Decoder 2Debian Linux | 18/12/2018 | 17/6/2026 | There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because the S_M array is mishandled. | |
| Modificada | Media (5.5) | 1.2% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 18/12/2018 | 17/6/2026 | A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | |
| Modificada | Alta (7.8) | 1.3% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 18/12/2018 | 17/6/2026 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impact because limiting the additional noise energy level is mishandled… |