Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

7726 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.24%—Adobe Substance 3D Viewer14/10/20258/10/2026
Las versiones 0.25.2 y anteriores de Substance3D - Viewer están afectadas por una vulnerabilidad de desbordamiento de búfer basado en pila que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que la…
AnalizadaAlta (7.8)0.19%—Adobe Substance 3D Viewer14/10/20258/10/2026
Las versiones 0.25.2 y anteriores de Substance3D - Viewer están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario, ya que una víctima debe abrir un…
AnalizadaAlta (7.8)0.22%—Adobe Substance 3D Stager16/9/202517/6/2026
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of…
AnalizadaMedia (5.5)0.24%—Adobe Substance 3D Stager16/9/202517/6/2026
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.21%—Adobe Substance 3D Modeler9/9/202517/6/2026
Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation…
AnalizadaAlta (7.8)0.21%—Adobe Substance 3D Modeler9/9/202517/6/2026
Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is unchanged.
AnalizadaAlta (7.8)0.21%—Adobe Substance 3D Viewer9/9/202517/6/2026
Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.21%—Adobe Substance 3D Viewer9/9/202517/6/2026
Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (5.5)0.22%—Adobe After Effects9/9/202517/6/2026
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (5.5)0.22%—Adobe After Effects9/9/202517/6/2026
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (5.5)0.22%—Adobe After Effects9/9/202517/6/2026
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.34%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat Reader9/9/202517/6/2026
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is…
AnalizadaMedia (4)0.27%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat Reader9/9/202517/6/2026
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user…
AnalizadaAlta (7.8)0.22%—Adobe Substance 3D Modeler9/9/20251/10/2026
Substance3D - Modeler versiones 1.22.2 y anteriores están afectadas por una vulnerabilidad de Use After Free que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en que una víctima debe abrir un archivo malicioso. El…
AnalizadaAlta (8.6)0.18%—Adobe Dreamweaver9/9/202517/6/2026
Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must click on a malicious link, and scope is changed.
AnalizadaAlta (7.8)0.22%—Adobe Premiere PRO9/9/202517/6/2026
Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file, and scope is unchanged.
AnalizadaAlta (7.8)0.26%—Adobe Substance 3D Viewer9/9/202530/9/2026
Substance3D - Las versiones 0.25.1 y anteriores de Viewer están afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que…
AnalizadaCrítica (10)22%—Adobe Coldfusion9/9/202517/6/2026
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.
AnalizadaMedia (5.4)5.3%—Adobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypassing security features within the application. Exploitation of…
AnalizadaMedia (4.3)1.8%💥 ExploitAdobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.
AnalizadaMedia (4.9)0.43%—Adobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.
AnalizadaAlta (7.7)5.8%—Adobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed
AnalizadaMedia (6.5)0.48%—Adobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.
AnalizadaMedia (6.5)0.42%—Adobe Experience Manager9/9/202517/6/2026
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.
AnalizadaMedia (6.5)2.0%💥 ExploitAdobe Experience Manager9/9/202530/9/2026
Versiones 6.5.23.0 y anteriores de Adobe Experience Manager están afectadas por una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) que podría resultar en una omisión de característica de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para manipular…