Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33. | |
| Modificada | Alta (7.8) | 0.33% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62. | |
| Modificada | Alta (7.8) | 0.34% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30. | |
| Modificada | Alta (7.8) | 0.34% | — | Irfanview | 16/9/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82. | |
| Modificada | Media (5.5) | 0.33% | — | Irfanview | 18/7/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba. | |
| Modificada | Media (5.5) | 0.24% | — | Irfanview | 18/7/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe. | |
| Modificada | Media (5.5) | 0.33% | — | Irfanview | 18/7/2022 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722. | |
| Modificada | Alta (7.8) | 1.1% | — | Irfanview | 23/3/2022 | 9/7/2026 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image. | |
| Modificada | Alta (7.8) | 1.3% | — | Irfanview | 15/12/2021 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531. | |
| Modificada | Media (5.5) | 0.72% | — | Xnview MP | 10/11/2021 | 17/6/2026 | XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33. | |
| Modificada | Media (5.5) | 0.98% | — | Xnview MP | 10/11/2021 | 17/6/2026 | XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree. | |
| Modificada | Media (5.5) | 0.93% | — | Irfanview | 5/11/2021 | 17/6/2026 | Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero starting at JPEG2000!ShowPlugInSaveOptions_W+0x00000000000082ea" | |
| Modificada | Media (5.5) | 0.81% | — | Irfanview | 5/11/2021 | 17/6/2026 | Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8. | |
| Modificada | Alta (7.8) | 1.1% | — | Irfanview | 5/11/2021 | 17/6/2026 | Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850". | |
| Modificada | Alta (7.8) | 0.97% | — | Irfanview | 28/10/2021 | 17/6/2026 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6". | |
| Modificada | Alta (7.8) | 0.96% | 💥 PoC | Irfanview | 28/10/2021 | 9/7/2026 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981. | |
| Modificada | Alta (7.8) | 0.98% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file. | |
| Modificada | Alta (7.8) | 0.98% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. |