Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.90%—Atos Unify Openscape 4000Atos Unify Openscape 4000 Manager6/4/202317/6/2026
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.
ModificadaCrítica (9.8)0.84%—Atos Unify Openscape 4000Atos Unify Openscape 4000 Manager6/4/202317/6/2026
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23552.
ModificadaCrítica (9.8)0.84%—Atos Unify Openscape 4000Atos Unify Openscape 4000 Manager6/4/202317/6/2026
webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23710.
ModificadaAlta (7.5)0.73%—Avanquest Pdfescape30/3/202317/6/2026
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaCrítica (9.8)1.9%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager13/12/202217/6/2026
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.
ModificadaAlta (7.8)0.25%—Hornerautomation Cscape15/11/202217/6/2026
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.
ModificadaAlta (7.8)0.24%—Hornerautomation Cscape27/10/202217/6/2026
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
ModificadaAlta (7.8)0.25%—Hornerautomation Cscape27/10/202217/6/2026
Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.
ModificadaAlta (7.5)1.4%—Shescape Project Shescape27/10/202217/6/2026
The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
ModificadaAlta (7.5)1.4%—Shescape Project Shescape6/9/202217/6/2026
Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shells `Bash` and `Dash`, or any not-officially-supported Unix shell; and/or using the `escape` or `escapeAll` functions with the…
ModificadaCrítica (9.8)1.9%—Shescape Project Shescape1/8/202217/6/2026
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to `true`. The result is that if an attacker is…
ModificadaCrítica (9.8)1.4%—Shescape Project Shescape1/8/202217/6/2026
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (any API function) to escape arguments for cmd.exe on Windows An attacker can omit all arguments following their input by including a line feed…
ModificadaCrítica (9.8)1.0%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller25/7/202217/6/2026
An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticated attacker (with network access to the admin interface) to…
ModificadaAlta (7.8)1.0%—Hornerautomation Cscape2/6/202217/6/2026
The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code
ModificadaAlta (7.8)0.91%—Hornerautomation Cscape2/6/202217/6/2026
The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)0.91%—Hornerautomation Cscape2/6/202217/6/2026
The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)0.89%—Hornerautomation Cscape2/6/202217/6/2026
The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)1.5%—Inkscape18/5/202217/6/2026
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
ModificadaBaja (3.3)0.96%—Inkscape18/5/202217/6/2026
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
ModificadaBaja (3.3)0.79%—Inkscape18/5/202217/6/2026
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
ModificadaAlta (7.1)0.71%—Hornerautomation Cscape Envisionrv25/3/202217/6/2026
This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is…
ModificadaMedia (5.5)0.50%—Shescape Project Shescape3/3/202217/6/2026
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`. Other tested shells, Dash and Zsh, are not…