Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.24% | — | Opensuse Cscreen | 16/3/2022 | 17/6/2026 | A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions. | |
| Modificada | Alta (7.5) | 0.96% | — | Xiaomi Mirror Screen | 18/1/2022 | 17/6/2026 | A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN. | |
| Modificada | Alta (7.8) | 0.19% | — | Zoom MeetingsZoom RoomsZoom Screen Sharing | 27/9/2021 | 17/6/2026 | It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts… | |
| Modificada | Crítica (9.1) | 2.0% | — | On24 Screenshare | 13/8/2021 | 17/6/2026 | The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path… | |
| Modificada | Media (5.4) | 0.62% | — | Prothemedesign Browser Screenshots | 12/7/2021 | 17/6/2026 | The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped. | |
| Modificada | Media (4.6) | 0.48% | — | Xscreensaver Project XscreensaverFedoraproject Fedora | 10/6/2021 | 17/6/2026 | XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs. | |
| Modificada | Crítica (9.8) | 1.8% | — | Deltaww Cncsoft Screeneditor | 16/5/2021 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 9.0% | — | Deltaww Cncsoft Screeneditor | 10/5/2021 | 17/6/2026 | Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Media (5.4) | 0.61% | — | Screenly | 29/4/2021 | 17/6/2026 | Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.32% | — | Xscreensaver Project Xscreensaver | 21/4/2021 | 17/6/2026 | The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency. | |
| Modificada | Crítica (9.8) | 9.1% | — | GNU ScreenDebian LinuxFedoraproject Fedora | 9/2/2021 | 17/6/2026 | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence. | |
| Modificada | Alta (7.8) | 2.1% | — | Deltaww Cncsoft Screeneditor | 11/1/2021 | 17/6/2026 | A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.9% | — | Deltaww Cncsoft Screeneditor | 4/8/2020 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application. | |
| Modificada | Baja (3.3) | 1.4% | — | Deltaww Cncsoft Screeneditor | 4/8/2020 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information. | |
| Modificada | Alta (7.8) | 9.5% | — | Deltaww Cncsoft Screeneditor | 4/8/2020 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application. | |
| Modificada | Alta (7.8) | 0.44% | — | Asus Screenpad2 Upgrade Tool | 20/7/2020 | 17/6/2026 | AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file… | |
| Modificada | Media (5.5) | 0.83% | — | Deltaww Cncsoft Screeneditor | 18/3/2020 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation. | |
| Modificada | Alta (7.8) | 1.1% | — | Deltaww Cncsoft Screeneditor | 18/3/2020 | 17/6/2026 | Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file. | |
| Modificada | Crítica (9.8) | 2.7% | — | GNU Screen | 24/2/2020 | 17/6/2026 | A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact. | |
| Modificada | Media (6.1) | 0.70% | — | Dicube Easescreen Crystal | 17/1/2020 | 17/6/2026 | Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication. | |
| Modificada | Alta (7.8) | 0.48% | — | Xscreensaver Project XscreensaverDebian Linux | 27/11/2019 | 16/6/2026 | xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication. | |
| Modificada | Media (5.5) | 1.0% | — | Deltaww Cnssoft Screeneditor | 24/7/2019 | 17/6/2026 | Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files. | |
| Modificada | Alta (7.8) | 1.4% | — | Deltaww Cnssoft Screeneditor | 24/7/2019 | 17/6/2026 | Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project… | |
| Modificada | Alta (7.8) | 2.9% | — | Deltaww Cncsoft Screeneditor | 17/4/2019 | 17/6/2026 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data… | |
| Modificada | Media (5.5) | 2.4% | — | Deltaww Cncsoft Screeneditor | 17/4/2019 | 17/6/2026 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files. |