Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files,… | |
| Analizada | Alta (7.8) | 0.22% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution. | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and… | |
| Analizada | Alta (7.8) | 0.17% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and… | |
| Analizada | Media (5.5) | 0.15% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to… | |
| Analizada | Alta (7.8) | 0.19% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local… | |
| Analizada | Alta (7.5) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 1/4/2026 | 17/6/2026 | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption,… | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 10/3/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.14% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 10/3/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user… | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 10/3/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Baja (3.4) | 0.11% | — | Darkreader | 4/3/2026 | 17/6/2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original web page), Dark… | |
| Aplazada | Media (5.9) | 0.24% | — | Silencesoft External RSS ReaderAIAJ Square INC RSS ReaderAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Stored XSS.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6. | |
| Aplazada | Media (6.4) | 0.12% | — | Unidocs Ezpdf DRM ReaderAIUnidocs Ezpdf ReaderAI | 15/2/2026 | 17/6/2026 | A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Such manipulation leads to uncontrolled search path. The attack needs to be performed locally. Attacks of this nature are highly complex. It is indicated that the… | |
| Analizada | Alta (7.5) | 0.44% | — | Sumatrapdfreader Sumatrapdf | 9/2/2026 | 17/6/2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installers without signature checks. A network attacker with any valid TLS certificate (e.g., Let's Encrypt) can intercept the… | |
| Analizada | Media (5.5) | 0.24% | — | Sumatrapdfreader Sumatrapdf | 9/2/2026 | 17/6/2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only validates half the range that DecodeOne() actually accesses. Opening a crafted .mobi file can read nearly (1 <<… | |
| Analizada | Alta (7.8) | 0.21% | — | Sumatrapdfreader Sumatrapdf | 9/2/2026 | 17/6/2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code execution on the victim’s system with the… | |
| Aplazada | Alta (8.1) | 0.54% | — | Comic Book ReaderAI | 4/2/2026 | 5/7/2026 | An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information. | |
| Modificada | Media (5) | 0.26% | — | Ntoolslab Office Reader | 4/2/2026 | 5/7/2026 | A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Analizada | Media (5.5) | 0.22% | — | Sumatrapdfreader Sumatrapdf | 22/1/2026 | 17/6/2026 | SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 records, causing an integer underflow in the size calculation. This bug exists in PalmDbReader::GetRecord when opening a crafted Mobi file, resulting in an out-of-bounds… | |
| Analizada | Alta (7.8) | 0.22% | — | Sumatrapdfreader Sumatrapdf | 14/1/2026 | 17/6/2026 | SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a… | |
| Analizada | Alta (7.8) | 0.30% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the calculation of the image buffer size may occur, potentially allowing a remote attacker to execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.21% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption. | |
| Analizada | Alta (7.8) | 0.21% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption. | |
| Analizada | Alta (7.8) | 0.21% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption. | |
| Analizada | Alta (7.8) | 0.30% | — | Foxit PDF EditorFoxit PDF Reader | 19/12/2025 | 17/6/2026 | A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote… |