Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.4%—Audiocoding Freeware Advanced Audio Decoder 223/11/201817/6/2026
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank.c.
ModificadaAlta (7.8)1.5%—Audiocoding Freeware Advanced Audio Decoder 223/11/201817/6/2026
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in the function calculate_gain() in libfaad/sbr_hfadj.c.
ModificadaAlta (7.8)1.7%—Audiocoding Freeware Advanced Audio Decoder 223/11/201817/6/2026
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.
ModificadaAlta (7.8)1.2%—Telerik JustassemblyTelerik Justdecompile16/8/201817/6/2026
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
ModificadaAlta (7.5)1.1%—Riptidecoin Project Riptidecoin9/7/201817/6/2026
The mintToken function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Riptidecoin Project Riptidecoin5/7/201817/6/2026
The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
ModificadaAlta (7.3)1.1%—Aprendecondedos Dedos-web5/6/201817/6/2026
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to…
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaCrítica (9.8)3.0%—Mcafee Cloud Analysis AND Deconstructive Services14/3/201717/6/2026
Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration error.
ModificadaMedia (6.1)0.95%—Bosch Bladecontrol-webvis6/7/201617/6/2026
Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.4)0.88%—Bosch Bladecontrol-webvis6/7/201617/6/2026
SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4)1.3%—Rhodecode Enterprise16/2/201517/6/2026
RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
ModificadaMedia (4)1.8%—Kallithea-scm KallitheaRhodecode Enterprise16/2/201517/6/2026
RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
ModificadaMedia (4.3)0.94%—Homepage Decorator Perltreebbs13/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlTreeBBS 2.30 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)1.1%—Moderndecoration Interior Design20/10/201417/6/2026
The Interior Design (aka com.interior.design.mcreda) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.