Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.25%—Irfanview EXR28/8/202417/6/2026
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).
AnalizadaMedia (5.5)0.28%—Irfanview EXR28/8/202417/6/2026
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).
AnalizadaAlta (7.8)0.55%—IrfanviewIrfanview WSQ21/8/202417/6/2026
IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (7.8)0.55%—IrfanviewIrfanview WSQ21/8/202417/6/2026
IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaMedia (6.5)1.1%💥 PoCXnview Nconvert28/2/202417/6/2026
Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.
ModificadaCrítica (9.8)0.56%—Irfanview B3D5/1/202417/6/2026
IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+1cbf heap-based out-of-bounds write.
ModificadaCrítica (9.8)0.56%—Irfanview B3D5/1/202417/6/2026
IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.
ModificadaCrítica (9.8)0.56%—Irfanview B3D5/1/202417/6/2026
IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.
ModificadaCrítica (9.8)0.74%—Xnview Classic29/12/202317/6/2026
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
ModificadaCrítica (9.8)0.58%—Xnview Classic29/12/202317/6/2026
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
ModificadaAlta (8.8)0.37%—Plainviewplugins Plainview Protect Passwords18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4.
ModificadaMedia (6.1)0.40%—Plainviewplugins Plainview Protect Passwords14/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions.
ModificadaAlta (7.8)0.20%—Xnview27/10/202317/6/2026
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
ModificadaAlta (7.8)0.54%—Xnview Nconvert19/10/202317/6/2026
XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)0.52%—Xnview Nconvert19/10/202317/6/2026
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.
ModificadaAlta (7.8)0.62%—Xnview Nconvert18/10/202317/6/2026
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
ModificadaAlta (7.8)0.22%—Jtekt Onsinview217/10/202317/6/2026
Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.
ModificadaAlta (7.8)0.20%—Jtekt Onsinview217/10/202317/6/2026
Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.
ModificadaAlta (8.8)0.25%—Plainviewplugins Mycryptocheckout3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions.
ModificadaAlta (7.8)0.34%—Xnview11/8/202317/6/2026
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
ModificadaAlta (7.8)0.27%—Xnview11/8/202317/6/2026
Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.
ModificadaMedia (6.1)0.85%💥 ExploitPlainviewplugins Mycryptocheckout2/5/202317/6/2026
The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
ModificadaMedia (5.5)0.55%—Irfanview4/4/202317/6/2026
Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.
ModificadaAlta (7.8)0.37%—Irfanview28/3/202317/6/2026
Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.
ModificadaCrítica (9.8)0.61%—Nview Project Nview5/1/202317/6/2026
A vulnerability has been found in Red Snapper NView and classified as critical. This vulnerability affects the function mutate of the file src/Session.php. The manipulation of the argument session leads to sql injection. The name of the patch is cbd255f55d476b29e5680f66f48c73ddb3d416a8. It is recommended to apply a…