Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.66% | — | Xilisoft Video Converter | 12/2/2020 | 17/6/2026 | Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability | |
| Modificada | Crítica (9.8) | 2.2% | — | EP Imageconvert Project EP Imageconvert | 10/1/2020 | 17/6/2026 | The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability | |
| Modificada | Alta (8.8) | 2.9% | — | Antennahouse Rainbow PDF Office Server Document Converter | 31/10/2019 | 17/6/2026 | A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro MR1 (7,0,2019,0220). While parsing a document text info container, the TxMasterStyleAtom::parse function is incorrectly checking the bounds corresponding to the number of style… | |
| Modificada | Alta (7.5) | 2.2% | — | Universal Office Converter Project Universal Office Converter | 21/10/2019 | 17/6/2026 | The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. | |
| Modificada | Alta (7.7) | 1.4% | — | Video Converter Project Video Converter | 19/10/2019 | 17/6/2026 | The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.) | |
| Modificada | Alta (7.5) | 1.6% | — | Convertplug Convertplus | 3/9/2019 | 17/6/2026 | The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants. | |
| Modificada | Alta (8.8) | 0.71% | — | Webp Converter FOR Media Project Webp Converter FOR Media | 30/8/2019 | 17/6/2026 | The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. | |
| Modificada | Alta (7.8) | 0.71% | — | Socusoft Photo 2 Video Converter | 24/7/2019 | 17/6/2026 | Socusoft Co Photo 2 Video Converter 8.0.0 is affected by: Buffer Overflow - Local shell-code execution and Denial of Service. The impact is: Local privilege escalation (dependant upon conditions), shell code execution and denial-of-service. The component is: pdmlog.dll library. The attack vector is: The attacker must… | |
| Modificada | Crítica (9.8) | 2.3% | — | Rainbowpdf Office Server Document Converter | 7/3/2019 | 17/6/2026 | A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1 (7,0,2018,1113). While parsing Document Summary Property Set stream, the getSummaryInformation function is incorrectly checking the correlation between size and the… | |
| Modificada | Media (5.5) | 1.1% | — | Byvoid Open Chinese Convert | 13/9/2018 | 17/6/2026 | Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset values via a crafted .ocd file. | |
| Modificada | Alta (7.5) | 1.1% | — | Currency Converter Script Project Currency Converter Script | 7/9/2018 | 17/6/2026 | PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma. | |
| Modificada | Alta (7.8) | 2.0% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. | |
| Modificada | Alta (7.8) | 2.1% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This… | |
| Modificada | Alta (7.8) | 2.5% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted Microsoft Word (DOC) document can lead to a stack-based buffer overflow, resulting in remote code… | |
| Modificada | Alta (7.8) | 2.5% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `putShapeProperty` method. | |
| Modificada | Alta (7.8) | 1.6% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `vbgetfp` method. | |
| Modificada | Alta (7.8) | 2.5% | — | Antennahouse Office Server Document Converter | 11/7/2018 | 17/6/2026 | An exploitable heap corruption exists in the PowerPoint document conversion functionality of the Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312). A crafted PowerPoint (PPT) document can lead to heap corruption, resulting in remote code execution. | |
| Modificada | Media (6.1) | 0.78% | — | 5000 Trillion YEN Converter Project 5000 Trillion YEN Converter | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in 5000 trillion yen converter v1.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 9.1% | 💥 Exploit | Convert Forms Project Convert Forms | 12/4/2018 | 17/6/2026 | The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file. | |
| Modificada | Crítica (9.8) | 5.9% | — | Adobe DNG Converter | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe DNG Converter 9.12.1 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Converto Video Downloader & Converter Project Converto Video Downloader & Converter | 29/10/2017 | 17/6/2026 | ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php. | |
| Modificada | Alta (7.8) | 5.5% | 💥 Exploit | ASX TO MP3 Converter Project ASX TO MP3 Converter | 16/10/2017 | 17/6/2026 | ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324. | |
| Modificada | Alta (7.8) | 0.50% | 💥 PoC | Ether Software Easy Avi/divx/xvid TO DVD BurnerEther Software Easy AVI Divx ConverterEther Software Easy CD DVD CopyEther Software Easy DVD Creator+14 | 30/4/2017 | 17/6/2026 | Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD… | |
| Modificada | Media (6.1) | 1.2% | — | Open-xchange Documentconverter-apiOpen-xchange Office WEBOpen-xchange Appsuite BackendOpen-xchange Appsuite Frontend | 29/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before… | |
| Modificada | Crítica (9.8) | 4.2% | — | Adobe DNG Converter | 15/12/2016 | 17/6/2026 | Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. |