Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use… | |
| Modificada | Media (5.5) | 0.25% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until… | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based… | |
| Modificada | Media (5.5) | 0.21% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Alta (7.8) | 0.91% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated Enhanced Metafile (.emf, emf.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of… | |
| Modificada | Media (5.5) | 0.21% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the… | |
| Modificada | Media (5.5) | 0.25% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application. | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of… | |
| Modificada | Media (5.5) | 0.25% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the… | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated CATIA4 Part (.model, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use… | |
| Modificada | Media (5.5) | 0.25% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the… | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated CATIA5 Part (.catpart, CatiaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use… | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of… | |
| Modificada | Media (5.5) | 0.25% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the… | |
| Modificada | Alta (7.8) | 0.37% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use… | |
| Modificada | Media (5.5) | 0.21% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens manipulated SolidWorks Drawing (.sldasm, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of… | |
| Modificada | Alta (7.8) | 0.56% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Drawing (.slddrw, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or… | |
| Modificada | Alta (7.8) | 0.54% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated Computer Graphics Metafile (.cgm, CgmTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or… | |
| Modificada | Alta (7.8) | 0.56% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated SolidWorks Part (.sldprt, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a… | |
| Modificada | Alta (7.8) | 0.56% | — | SAP 3D Visual Enterprise Author | 11/10/2022 | 17/6/2026 | Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or… | |
| Modificada | Media (6.1) | 0.47% | — | Sync Oxygen Publishing EngineSync Oxygen XML AuthorSync Oxygen XML DeveloperSync Oxygen XML Editor+1 | 13/7/2022 | 17/6/2026 | An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp… | |
| Modificada | Alta (7.5) | 5.0% | — | Powerdns Authoritative ServerPowerdns RecursorFedoraproject Fedora | 25/3/2022 | 17/6/2026 | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers. | |
| Modificada | Media (4.8) | 0.63% | — | Jenkins Folder-based Authorization Strategy | 15/3/2022 | 17/6/2026 | Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Crítica (9.8) | 2.1% | — | Quest Kace Desktop Authority | 22/12/2021 | 17/6/2026 | An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}. |