Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3562 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.38%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat Reader9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat Reader9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.38%—Adobe AcrobatAdobe Acrobat Reader9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.26%—Adobe AcrobatAdobe Acrobat Reader9/6/202628/8/2026
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaCrítica (9.3)0.22%—Kavitareader KavitaAI26/5/202624/7/2026
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.
AplazadaMedia (5.9)0.39%—Kavitareader KavitaAI26/5/202624/7/2026
Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or guesses a chapterId, volumeId, or seriesId belonging to a library they are not assigned to can download the full file…
AplazadaMedia (6.9)0.43%—Kavitareader KavitaAI26/5/202624/7/2026
Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from any chapter in any library. While the endpoint accepts an apiKey parameter, it is never validated. Since entity IDs are…
AplazadaMedia (5.5)0.51%—ExifreaderAI19/5/202623/7/2026
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly…
AplazadaAlta (7.7)0.61%—ExifreaderAI19/5/202623/7/2026
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation,…
AplazadaBaja (2.1)0.43%—Investintech SlimpdfereaderAI17/5/202617/6/2026
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The…
AnalizadaAlta (7.8)0.17%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
AnalizadaAlta (7.1)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.
AnalizadaMedia (5.5)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
AnalizadaMedia (5.5)0.16%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
AnalizadaMedia (5.5)0.15%—Foxit PDF EditorFoxit PDF Reader27/4/202617/6/2026
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.
AnalizadaMedia (6.3)0.58%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC14/4/202628/8/2026
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires…
AnalizadaAlta (8.6)0.67%—Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DC14/4/202628/8/2026
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
AnalizadaAlta (8.6)2.2%⚠ Explotación activaAdobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat11/4/202628/8/2026
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
AplazadaAlta (8.4)0.21%—Docudepot PDF Reader PDF Viewer APPAI1/4/202617/6/2026
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AplazadaAlta (8.4)0.21%—ORA Tools PDF Reader Reader Editor APPAI1/4/202617/6/2026
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.