Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 7.1% | — | Adobe Photoshop | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable use-after-free vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 8.1% | — | Adobe Photoshop | 9/12/2017 | 17/6/2026 | An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (8.1) | 0.88% | — | Photosynth Akerun | 21/4/2017 | 17/6/2026 | Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates. | |
| Modificada | Crítica (9.8) | 2.3% | 💥 Exploit | Ktools Photostore | 12/4/2017 | 17/6/2026 | SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action. | |
| Modificada | Alta (7.8) | 0.90% | — | Adobe Photoshop CC | 12/4/2017 | 17/6/2026 | Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. | |
| Modificada | Alta (7.8) | 5.6% | — | Adobe Photoshop CC | 12/4/2017 | 17/6/2026 | Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have a memory corruption vulnerability when parsing malicious PCX files. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Adobe Bridge CCAdobe Photoshop CC | 10/2/2016 | 17/6/2026 | Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Adobe BridgeAdobe Photoshop CC | 24/6/2015 | 17/6/2026 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Alta (10) | 19% | 💥 Exploit | Adobe BridgeAdobe Photoshop CC | 24/6/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Adobe Photoshop CCAdobe Bridge | 24/6/2015 | 17/6/2026 | Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 5.1% | — | Adobe Photoshop CC | 24/6/2015 | 17/6/2026 | Adobe Photoshop CC before 16.0 (aka 2015.0.0) allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Photosmash Project Photosmash | 1/1/2015 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (9.3) | 23% | 💥 Exploit | Adobe Photoshop CS5Adobe Photoshop Cs5.1 | 19/6/2014 | 16/6/2026 | Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element. | |
| Modificada | Alta (10) | 9.0% | — | Adobe Photoshop Cs5.5Adobe Photoshop CS6 | 4/9/2012 | 16/6/2026 | Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Adobe Photoshop CS6 | 31/8/2012 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Alta (7.8) | 2.3% | — | HP Photosmart E-all-in-one Printer SeriesHP Photosmart Estation All-in-one-printer SeriesHP Photosmart INK Advantage E-all-in-oneHP Photosmart Plus E-all-in-one Printer Series+2 | 30/6/2012 | 16/6/2026 | Unspecified vulnerability on HP Photosmart Wireless e-All-in-One B110, e-All-in-One D110, Plus e-All-in-One B210, eStation All-in-One C510, Ink Advantage e-All-in-One K510, and Premium Fax e-All-in-One C410 printers allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (9.3) | 7.0% | — | Adobe PhotoshopAdobe Photoshop CS4Adobe Photoshop Cs5.5 | 9/5/2012 | 16/6/2026 | Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Adobe PhotoshopAdobe Photoshop CS4Adobe Photoshop Cs5.5 | 9/5/2012 | 16/6/2026 | Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF) file. | |
| Modificada | Alta (9.3) | 14% | 💥 Exploit | Adobe Photoshop Elements | 4/10/2011 | 16/6/2026 | Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296. | |
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Adobe Creative SuiteAdobe Photoshop | 11/8/2011 | 16/6/2026 | Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file. | |
| Modificada | Alta (10) | 3.8% | — | Adobe Photoshop | 20/5/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Adobe Photoshop before 12.0.4 have unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 2.1% | — | HP Envy 100 D410HP Photosmart B110HP Photosmart D110HP Photosmart Plus B210+3 | 15/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.0% | — | HP Envy 100 D410HP Photosmart B110HP Photosmart D110HP Photosmart Plus B210+3 | 15/4/2011 | 16/6/2026 | Unspecified vulnerability in the SNMP component on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to obtain sensitive information or modify data via vectors related to the Embedded Web Server (EWS). |