Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)3.8%—Adobe Animate11/2/202117/6/2026
Adobe Animate version 21.0.2 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.5)1.6%💥 PoCGreensock Animation Platform19/1/202117/6/2026
This affects the package gsap before 3.6.0.
ModificadaAlta (7)2.4%—Adobe Animate13/1/202117/6/2026
Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)4.5%—Adobe Animate21/10/202017/6/2026
Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability, which could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file in Animate.
ModificadaAlta (7.8)4.1%—Adobe Animate21/10/202017/6/2026
Adobe Animate version 20.5 (and earlier) is affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file in Animate.
ModificadaAlta (7.8)6.3%—Adobe Animate21/10/202017/6/2026
Adobe Animate version 20.5 (and earlier) is affected by a stack overflow vulnerability, which could lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .fla file in Animate.
ModificadaAlta (7.8)4.1%—Adobe Animate21/10/202017/6/2026
Adobe Animate version 20.5 (and earlier) is affected by a double free vulnerability when parsing a crafted .fla file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
ModificadaAlta (7.8)7.6%—Adobe Character Animator26/6/202017/6/2026
Adobe Character Animator versions 3.2 and earlier have a buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)0.78%—Adobe Animate CC14/11/201917/6/2026
Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
ModificadaAlta (8.8)0.86%—Eleopard Animate IT!10/10/201917/6/2026
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
ModificadaMedia (6.1)0.94%—Eleopard Animate IT!9/10/201917/6/2026
The animate-it plugin before 2.3.5 for WordPress has XSS.
ModificadaMedia (6.1)0.94%—Eleopard Animate IT!9/10/201917/6/2026
The animate-it plugin before 2.3.4 for WordPress has XSS.
ModificadaAlta (7.8)3.8%—Adobe Character Animator14/8/201917/6/2026
Adobe Character Animator versions 2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (8.8)2.4%—Disneyanimation Ptex29/1/201817/6/2026
An exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known as PTEX. The vulnerability is present in the reading of a file without proper parameter checking. The value read in, is not verified to be valid and its use can lead to a buffer overflow,…
ModificadaCrítica (9.8)16%💥 ExploitAdobe Animate15/12/201617/6/2026
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
ModificadaAlta (7.5)3.9%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
ModificadaAlta (7.5)2.2%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (6.3)1.1%—Sharp EVA Animator5/4/201617/6/2026
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
ModificadaMedia (5)1.8%—Magnifica Webscripts Anima Gallery10/6/201517/6/2026
Multiple directory traversal vulnerabilities in func.php in Magnifica Webscripts Anima Gallery 2.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) theme or (2) lang cookie parameter to AnimaGallery/.
ModificadaMedia (5.4)0.27%—Animalcenter Light FOR Pets29/9/201417/6/2026
The Light for Pets (aka com.helenwoodward.light4pets) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Topappsbuilder Project Animal Kaiser Zangetsu20/9/201417/6/2026
The Animal Kaiser Zangetsu (aka com.wAnimalKaiserZangetsu) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Gameloft Wonder ZOO - Animal Rescue !9/9/201417/6/2026
The Wonder Zoo - Animal rescue ! (aka com.gameloft.android.ANMP.GloftZRHM) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Ilearnwith Animals! Kids Preschool Games9/9/201417/6/2026
The Animals! Kids Preschool Games (aka air.com.tribalnova.Animals) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades