Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Ayuntamientodecoana Ayuntamiento DE Coana19/10/201417/6/2026
The Ayuntamiento de Coana (aka com.wInfoCoa) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)1.1%—Decoracionesnailart Designs Nail Arts19/9/201417/6/2026
The Designs Nail Arts (aka com.decoracionesnailart.flickr) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.1%—Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer29/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.9)0.41%—Vmware Movie Decoder5/10/201216/6/2026
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
ModificadaMedia (6.9)0.40%—Sothink SWF Decompiler7/9/201216/6/2026
Untrusted search path vulnerability in Sothink SWF Decompiler 6.0 Build 610 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .flv file. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%—Milesj Decoda3/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags.
ModificadaMedia (4.3)2.5%💥 ExploitMilesj Decoda3/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.1 allows remote attackers to inject arbitrary web script or HTML via multiple URLs in an img tag.
ModificadaMedia (4.3)3.8%💥 ExploitMilesj Decoda3/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in decoda/templates/video.php in Decoda before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via the video directive.
ModificadaAlta (9.3)5.8%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server6/12/201016/6/2026
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build…
ModificadaMedia (6.9)0.28%—Ponsoftware Archive Decoder25/10/201016/6/2026
Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.
ModificadaAlta (9.3)6.2%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server12/4/201016/6/2026
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file…
ModificadaAlta (9.3)6.2%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server12/4/201016/6/2026
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute…
ModificadaAlta (9.3)5.6%—Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation8/9/200916/6/2026
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might…
ModificadaAlta (9.3)5.0%—Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation8/9/200916/6/2026
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute…
ModificadaAlta (9.3)3.3%—Decomputeur Toolbar Uninstaller25/8/200916/6/2026
Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website."
ModificadaAlta (9.3)5.7%—Foxitsoftware Jpeg2000 Jbig2 Decoder Add-onFoxitsoftware Foxit Reader23/6/200916/6/2026
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary…
ModificadaAlta (9.3)5.7%—Foxitsoftware Foxit ReaderFoxitsoftware Jpeg2000/jbig2 Decoder Add-on23/6/200916/6/2026
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute…
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies 1D Barcode Decoder Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (7.5)2.4%💥 ExploitDivideconcept VHD WEB Pack6/2/200816/6/2026
Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaAlta (10)13%💥 ExploitDigital Data Communications Rtspvapgdecoder.dll22/1/200816/6/2026
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.
ModificadaAlta (10)3.0%—Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP6/9/200716/6/2026
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote…
ModificadaAlta (9)2.1%—Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP6/9/200716/6/2026
The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows…
ModificadaAlta (10)6.0%💥 ExploitNobreak Technologies CrazywwwboardQdecoder3/5/200116/6/2026
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.
Orbitaley — Vulnerabilidades