Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Ayuntamientodecoana Ayuntamiento DE Coana | 19/10/2014 | 17/6/2026 | The Ayuntamiento de Coana (aka com.wInfoCoa) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 1.1% | — | Decoracionesnailart Designs Nail Arts | 19/9/2014 | 17/6/2026 | The Designs Nail Arts (aka com.decoracionesnailart.flickr) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer | 29/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.9) | 0.41% | — | Vmware Movie Decoder | 5/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory. | |
| Modificada | Media (6.9) | 0.40% | — | Sothink SWF Decompiler | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Sothink SWF Decompiler 6.0 Build 610 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .flv file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | — | Milesj Decoda | 3/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Milesj Decoda | 3/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Milesj Decoda | 3/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive. | |
| Modificada | Alta (9.3) | 5.8% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 6/12/2010 | 16/6/2026 | The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build… | |
| Modificada | Media (6.9) | 0.28% | — | Ponsoftware Archive Decoder | 25/10/2010 | 16/6/2026 | Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory. | |
| Modificada | Alta (9.3) | 6.2% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 12/4/2010 | 16/6/2026 | vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file… | |
| Modificada | Alta (9.3) | 6.2% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 12/4/2010 | 16/6/2026 | Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute… | |
| Modificada | Alta (9.3) | 5.6% | — | Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation | 8/9/2009 | 16/6/2026 | The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might… | |
| Modificada | Alta (9.3) | 5.0% | — | Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation | 8/9/2009 | 16/6/2026 | Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute… | |
| Modificada | Alta (9.3) | 3.3% | — | Decomputeur Toolbar Uninstaller | 25/8/2009 | 16/6/2026 | Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website." | |
| Modificada | Alta (9.3) | 5.7% | — | Foxitsoftware Jpeg2000 Jbig2 Decoder Add-onFoxitsoftware Foxit Reader | 23/6/2009 | 16/6/2026 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary… | |
| Modificada | Alta (9.3) | 5.7% | — | Foxitsoftware Foxit ReaderFoxitsoftware Jpeg2000/jbig2 Decoder Add-on | 23/6/2009 | 16/6/2026 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | |
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies 1D Barcode Decoder Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Divideconcept VHD WEB Pack | 6/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Digital Data Communications Rtspvapgdecoder.dll | 22/1/2008 | 16/6/2026 | Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property. | |
| Modificada | Alta (10) | 3.0% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote… | |
| Modificada | Alta (9) | 2.1% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows… | |
| Modificada | Alta (10) | 6.0% | 💥 Exploit | Nobreak Technologies CrazywwwboardQdecoder | 3/5/2001 | 16/6/2026 | Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header. |