Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.38% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe AcrobatAdobe Acrobat Reader | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe AcrobatAdobe Acrobat Reader | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe AcrobatAdobe Acrobat Reader | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe AcrobatAdobe Acrobat Reader | 9/6/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Crítica (9.3) | 0.22% | — | Kavitareader KavitaAI | 26/5/2026 | 24/7/2026 | Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2. | |
| Aplazada | Media (5.9) | 0.39% | — | Kavitareader KavitaAI | 26/5/2026 | 24/7/2026 | Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or guesses a chapterId, volumeId, or seriesId belonging to a library they are not assigned to can download the full file… | |
| Aplazada | Media (6.9) | 0.43% | — | Kavitareader KavitaAI | 26/5/2026 | 24/7/2026 | Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from any chapter in any library. While the endpoint accepts an apiKey parameter, it is never validated. Since entity IDs are… | |
| Aplazada | Media (5.5) | 0.51% | — | ExifreaderAI | 19/5/2026 | 23/7/2026 | Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly… | |
| Aplazada | Alta (7.7) | 0.61% | — | ExifreaderAI | 19/5/2026 | 23/7/2026 | This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation,… | |
| Aplazada | Baja (2.1) | 0.43% | — | Investintech SlimpdfereaderAI | 17/5/2026 | 17/6/2026 | A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The… | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program. | |
| Analizada | Alta (7.1) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes. | |
| Analizada | Media (5.5) | 0.16% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 27/4/2026 | 17/6/2026 | Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate. | |
| Analizada | Media (6.3) | 0.58% | — | Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC | 14/4/2026 | 28/8/2026 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires… | |
| Analizada | Alta (8.6) | 0.67% | — | Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC | 14/4/2026 | 28/8/2026 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires… | |
| Analizada | Alta (8.6) | 2.2% | ⚠ Explotación activa | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 11/4/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | |
| Aplazada | Alta (8.4) | 0.21% | — | Docudepot PDF Reader PDF Viewer APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Alta (8.4) | 0.21% | — | ORA Tools PDF Reader Reader Editor APPAI | 1/4/2026 | 17/6/2026 | An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. |