Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.98% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. | |
| Modificada | Media (5.5) | 0.66% | — | Irfanview | 28/9/2021 | 17/6/2026 | Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS). | |
| Modificada | Alta (7.8) | 1.0% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in Formats!ReadRAS_W+0x1001 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. | |
| Modificada | Alta (7.8) | 1.0% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa74 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.0xa74 | |
| Modificada | Alta (7.8) | 1.0% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. | |
| Modificada | Alta (7.8) | 1.0% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x340 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. | |
| Modificada | Alta (7.8) | 1.0% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x37a of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file. | |
| Modificada | Media (5.5) | 0.67% | — | Irfanview | 28/9/2021 | 17/6/2026 | A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file. | |
| Modificada | Alta (7.5) | 2.0% | — | Planview Spigit | 5/8/2021 | 17/6/2026 | The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as demonstrated by an api/v1/users/1 request. | |
| Modificada | Crítica (9.8) | 4.5% | — | Irfanview WPG | 17/2/2021 | 17/6/2026 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 38% | — | Irfanview WPG | 17/2/2021 | 17/6/2026 | The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 4.4% | — | Irfanview | 16/12/2020 | 17/6/2026 | irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60. | |
| Modificada | Alta (7.8) | 1.1% | — | Irfanview | 10/6/2020 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7. | |
| Modificada | Alta (8.8) | 3.2% | — | Irfanview | 10/6/2020 | 17/6/2026 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4. | |
| Modificada | Media (4.8) | 1.5% | 💥 PoC | Rubyonrails ActionviewDebian LinuxFedoraproject FedoraOpensuse Leap | 19/3/2020 | 17/6/2026 | In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2. | |
| Modificada | Crítica (9.8) | 1.6% | — | Xnview | 27/1/2020 | 16/6/2026 | XnView 2.03 has an integer overflow vulnerability | |
| Modificada | Crítica (9.8) | 1.5% | — | Xnview | 27/1/2020 | 16/6/2026 | XnView 2.03 has a stack-based buffer overflow vulnerability | |
| Modificada | Crítica (9.6) | 1.8% | — | Irfanview Flashpix Plugin | 27/1/2020 | 16/6/2026 | IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability | |
| Modificada | Crítica (9.8) | 2.8% | — | Xnview | 2/1/2020 | 16/6/2026 | Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 1.7% | — | Xnview | 2/1/2020 | 16/6/2026 | xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 1.7% | — | Xnview | 2/1/2020 | 16/6/2026 | Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file. | |
| Modificada | Alta (7.8) | 2.4% | — | Xnview | 2/1/2020 | 16/6/2026 | Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file. | |
| Modificada | Alta (7.8) | 2.4% | — | Xnview | 2/1/2020 | 16/6/2026 | Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file. | |
| Modificada | Alta (7.8) | 0.44% | — | Xnview | 8/10/2019 | 17/6/2026 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0. | |
| Modificada | Alta (7.8) | 0.44% | — | Xnview | 8/10/2019 | 17/6/2026 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51. |