Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.78% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted… | |
| Modificada | Alta (7.8) | 0.78% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICO files. Crafted… | |
| Modificada | Alta (7.8) | 0.79% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted… | |
| Modificada | Alta (7.8) | 0.79% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted… | |
| Modificada | Alta (7.8) | 0.78% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted… | |
| Modificada | Media (5.5) | 0.74% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files.… | |
| Modificada | Media (5.5) | 0.74% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WMF files.… | |
| Modificada | Media (5.5) | 0.88% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files.… | |
| Modificada | Alta (7.8) | 0.78% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Collab objects. By… | |
| Modificada | Alta (7.8) | 0.78% | — | Pdf-xchange Editor | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the submitForm method. By performing… | |
| Modificada | Alta (7.8) | 0.23% | — | Pdf-xchange Editor | 28/3/2023 | 17/6/2026 | A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file. | |
| Modificada | Alta (7.8) | 1.0% | — | Foxit PDF EditorFoxit PDF Reader | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images.… | |
| Modificada | Alta (7.8) | 1.0% | — | Foxit PDF EditorFoxit PDF Reader | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images.… | |
| Modificada | Media (6.1) | 0.73% | — | CkeditorFedoraproject Fedora | 22/3/2023 | 17/6/2026 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with… | |
| Modificada | Crítica (9.6) | 0.95% | — | Markdown Edit Project Markdown Edit | 16/3/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the webpage. | |
| Modificada | Media (6.1) | 0.32% | — | Quickentity Editor Project Quickentity Editor | 6/3/2023 | 17/6/2026 | quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name.… | |
| Modificada | Alta (7.8) | 0.58% | 💥 PoC | Live2d Cubism Editor | 3/3/2023 | 17/6/2026 | Cubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info Table in an MOC3 file. | |
| Modificada | Media (5.4) | 0.40% | — | Wangeditor | 27/2/2023 | 17/6/2026 | WangEditor v5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /dist/index.js. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Ckeditor | 13/2/2023 | 17/6/2026 | Se descubrió que CKSource CKEditor 5 35.4.0 contiene una vulnerabilidad de cross-site scripting (XSS) a través del widget CKEditor5 con todas las funciones. NOTA: la posición del proveedor es que esto no es una vulnerabilidad. La documentación de CKEditor 5 analiza que es responsabilidad de un integrador (que agrega… | |
| Modificada | Alta (7.8) | 4.9% | — | Deltaww CncsoftDeltaww Screeneditor | 3/2/2023 | 17/6/2026 | Todas las versiones anteriores a la versión 1.01.34 de CNCSoft de Delta Electronic (que ejecutan las versiones 1.01.5 y anteriores de ScreenEditor) son vulnerables a un desbordamiento del búfer en la región stack de la memoria, lo que podría permitir a un atacante ejecutar código arbitrario de forma remota. | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Alta (8.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.1) | 0.21% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM. | |
| Modificada | Alta (7.8) | 0.97% | — | Editorconfig | 1/2/2023 | 17/6/2026 | A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write operations over the p_pcre buffer. |