Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate. | |
| Analizada | Alta (8.6) | 0.21% | — | Magix Music Editor Deluxe | 22/4/2026 | 17/6/2026 | MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and… | |
| Aplazada | Alta (8.6) | 0.19% | — | Editorconfig-core-cAI | 18/4/2026 | 17/6/2026 | editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in ec_glob() that allows an attacker to crash any application using libeditorconfig by providing a specially crafted directory structure and… | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | Onlyoffice DesktopeditorsAI | 16/4/2026 | 17/6/2026 | In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges. | |
| Aplazada | Media (4.3) | 0.16% | — | Pluginus Bear Bulk Editor AND Products Manager ProfessionalAI | 8/4/2026 | 24/7/2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Mndpsingh287 Theme EditorAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2. | |
| Aplazada | Media (5.5) | 0.47% | — | Huimeicloud HM EditorAI | 2/4/2026 | 24/7/2026 | A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (8.4) | 0.21% | — | ORA Tools PDF Reader Reader Editor APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files,… | |
| Analizada | Alta (7.8) | 0.22% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and… | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and… | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to… | |
| Analizada | Alta (7.8) | 0.19% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local… | |
| Analizada | Alta (7.5) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption,… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Syarif Mobile APP EditorAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Janis Elsts Admin Menu EditorAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Request Forgery.This issue affects Admin Menu Editor: from n/a through <= 1.14.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Marketing Fire Editorial CalendarAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows DOM-Based XSS.This issue affects Editorial Calendar: from n/a through <= 3.9.0. | |
| Aplazada | Alta (7.2) | 0.42% | — | Themehelper Checkout Field EditorAI | 11/3/2026 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the… | |
| Aplazada | Media (5.9) | 0.22% | — | Guest Posting Frontend Posting Front EditorAI | 11/3/2026 | 17/6/2026 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor… | |
| Aplazada | Media (6.4) | 0.16% | — | Media Library ALT Text EditorAI | 7/3/2026 | 17/6/2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |