Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.4% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 23/11/2018 | 17/6/2026 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank.c. | |
| Modificada | Alta (7.8) | 1.5% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 23/11/2018 | 17/6/2026 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in the function calculate_gain() in libfaad/sbr_hfadj.c. | |
| Modificada | Alta (7.8) | 1.7% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 23/11/2018 | 17/6/2026 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c. | |
| Modificada | Alta (7.8) | 1.2% | — | Telerik JustassemblyTelerik Justdecompile | 16/8/2018 | 17/6/2026 | An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource. | |
| Modificada | Alta (7.5) | 1.1% | — | Riptidecoin Project Riptidecoin | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Riptidecoin Project Riptidecoin | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.3) | 1.1% | — | Aprendecondedos Dedos-web | 5/6/2018 | 17/6/2026 | In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to… | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Crítica (9.8) | 3.0% | — | Mcafee Cloud Analysis AND Deconstructive Services | 14/3/2017 | 17/6/2026 | Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration error. | |
| Modificada | Media (6.1) | 0.95% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 0.88% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4) | 1.3% | — | Rhodecode Enterprise | 16/2/2015 | 17/6/2026 | RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method. | |
| Modificada | Media (4) | 1.8% | — | Kallithea-scm KallitheaRhodecode Enterprise | 16/2/2015 | 17/6/2026 | RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method. | |
| Modificada | Media (4.3) | 0.94% | — | Homepage Decorator Perltreebbs | 13/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlTreeBBS 2.30 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.1% | — | Moderndecoration Interior Design | 20/10/2014 | 17/6/2026 | The Interior Design (aka com.interior.design.mcreda) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |