Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Edrawsoft Edraw MAX | 19/6/2019 | 17/6/2026 | Edraw Max 7.9.3 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a77. | |
| Modificada | Alta (7.8) | 1.5% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code… | |
| Modificada | Alta (7.8) | 1.8% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out-of-bounds write exists in the CALS Raster file format-parsing functionality of Canvas Draw version 5.0.0.28. A specially crafted CAL image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a CAL image to trigger this vulnerability… | |
| Modificada | Alta (7.8) | 1.9% | — | Canvasgfx Canvas Draw | 6/2/2019 | 17/6/2026 | An exploitable out of bounds write exists in the CAL parsing functionality of Canvas Draw version 5.0.0. A specially crafted CAL image processed via the application can lead to an out of bounds write overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution. | |
| Modificada | Alta (8.1) | 2.2% | — | Opendesign Drawings SDKOracle Outside IN Technology | 19/10/2018 | 17/6/2026 | A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or… | |
| Modificada | Alta (8.1) | 2.2% | — | Opendesign Drawings SDKOracle Outside IN Technology | 19/10/2018 | 17/6/2026 | Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash. | |
| Modificada | Alta (7.8) | 2.3% | — | Canvasgfx Canvas Draw | 1/10/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. | |
| Modificada | Crítica (9.6) | 1.6% | — | Latexdraw Project Latexdraw | 20/8/2018 | 17/6/2026 | LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file. | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability… | |
| Modificada | Alta (7.8) | 1.8% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code… | |
| Modificada | Alta (7.8) | 1.5% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to… | |
| Modificada | Alta (7.8) | 1.8% | — | Acdsystems Canvas Draw | 19/7/2018 | 17/6/2026 | An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A… | |
| Modificada | Alta (7.8) | 1.2% | — | Coreldraw Photo Paint X8 | 24/4/2018 | 17/6/2026 | A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific TIFF file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 1.1% | — | Coreldraw Photo Paint X8 | 24/4/2018 | 17/6/2026 | A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 version 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific TIFF file to trigger this vulnerability. This… | |
| Modificada | Alta (7.8) | 2.6% | — | Coreldraw | 24/4/2018 | 17/6/2026 | An out of bound write vulnerability exists in the EMF parsing functionality of CorelDRAW X8 (CdrGfx - Corel Graphics Engine (64-Bit) - 18.1.0.661). A specially crafted EMF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific EMF file to trigger this… | |
| Modificada | Alta (7.8) | 2.2% | — | Coreldraw Photo Paint X8 | 24/4/2018 | 17/6/2026 | An of bound write / memory corruption vulnerability exists in the GIF parsing functionality of Core PHOTO-PAINT X8 18.1.0.661. A specially crafted GIF file can cause a vulnerability resulting in potential memory corruption resulting in code execution. An attacker can send the victim a specific GIF file to trigger this… | |
| Modificada | Alta (7.8) | 8.3% | 💥 Exploit | CoreldrawCoreldraw Photo PaintCorel Paint Shop PROCorel Painter+1 | 29/8/2017 | 17/6/2026 | DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Jpchacha Chasys Draw IES | 11/3/2014 | 16/6/2026 | Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file. | |
| Modificada | Media (6.9) | 2.8% | 💥 Exploit | Coreldraw X5Corel Photo-paint X3 | 7/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a directory that contains a .cdr, .cpt, .cmx, or .csl file. NOTE: some of… | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Mediachance Real-draw PRO | 27/5/2012 | 16/6/2026 | MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (1) PNG, (2) WMF, (3) PSD, (4) TGA, (5) TTF, (6) BMP, (7) TIFF, or (8) PCX file. | |
| Modificada | Media (6.8) | 8.4% | 💥 Exploit | Joomlacomponent.inetlanka COM Drawroot | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (9.3) | 4.5% | 💥 Exploit | Edraw PDF Viewer Component | 22/6/2009 | 16/6/2026 | Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and overwrite arbitrary files via a URL argument to the FtpConnect argument and a target filename argument to the FtpDownloadFile method. NOTE:… | |
| Modificada | Alta (9.3) | 3.7% | 💥 Exploit | Edraw Flowchart Activex | 5/11/2007 | 16/6/2026 | Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420. |