Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.24%—Opensuse Cscreen16/3/202217/6/2026
A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen and a system DoS for non-default systems. This issue affects: openSUSE Factory cscreen version 1.2-1.3 and prior versions.
ModificadaAlta (7.5)0.96%—Xiaomi Mirror Screen18/1/202217/6/2026
A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.
ModificadaAlta (7.8)0.19%—Zoom MeetingsZoom RoomsZoom Screen Sharing27/9/202117/6/2026
It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts…
ModificadaCrítica (9.1)2.0%—On24 Screenshare13/8/202117/6/2026
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path…
ModificadaMedia (5.4)0.62%—Prothemedesign Browser Screenshots12/7/202117/6/2026
The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.
ModificadaMedia (4.6)0.48%—Xscreensaver Project XscreensaverFedoraproject Fedora10/6/202117/6/2026
XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.
ModificadaCrítica (9.8)1.8%—Deltaww Cncsoft Screeneditor16/5/202117/6/2026
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)9.0%—Deltaww Cncsoft Screeneditor10/5/202117/6/2026
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.
ModificadaMedia (5.4)0.61%—Screenly29/4/202117/6/2026
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code.
ModificadaAlta (7.8)0.32%—Xscreensaver Project Xscreensaver21/4/202117/6/2026
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.
ModificadaCrítica (9.8)9.1%—GNU ScreenDebian LinuxFedoraproject Fedora9/2/202117/6/2026
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
ModificadaAlta (7.8)2.1%—Deltaww Cncsoft Screeneditor11/1/202117/6/2026
A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)1.9%—Deltaww Cncsoft Screeneditor4/8/202017/6/2026
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
ModificadaBaja (3.3)1.4%—Deltaww Cncsoft Screeneditor4/8/202017/6/2026
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.
ModificadaAlta (7.8)9.5%—Deltaww Cncsoft Screeneditor4/8/202017/6/2026
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
ModificadaAlta (7.8)0.44%—Asus Screenpad2 Upgrade Tool20/7/202017/6/2026
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file…
ModificadaMedia (5.5)0.83%—Deltaww Cncsoft Screeneditor18/3/202017/6/2026
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.
ModificadaAlta (7.8)1.1%—Deltaww Cncsoft Screeneditor18/3/202017/6/2026
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.
ModificadaCrítica (9.8)2.7%—GNU Screen24/2/202017/6/2026
A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.
ModificadaMedia (6.1)0.70%—Dicube Easescreen Crystal17/1/202017/6/2026
Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authentication.
ModificadaAlta (7.8)0.48%—Xscreensaver Project XscreensaverDebian Linux27/11/201916/6/2026
xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.
ModificadaMedia (5.5)1.0%—Deltaww Cnssoft Screeneditor24/7/201917/6/2026
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.
ModificadaAlta (7.8)1.4%—Deltaww Cnssoft Screeneditor24/7/201917/6/2026
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project…
ModificadaAlta (7.8)2.9%—Deltaww Cncsoft Screeneditor17/4/201917/6/2026
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data…
ModificadaMedia (5.5)2.4%—Deltaww Cncsoft Screeneditor17/4/201917/6/2026
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files.
Orbitaley — Vulnerabilidades