Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3562 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4) | 0.27% | — | Adobe AcrobatAdobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat Reader | 9/9/2025 | 17/6/2026 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not require user… | |
| Aplazada | Alta (8.8) | 0.77% | — | Microsoft Asp.netAIMicrosoft Diasymreader.dllAI | 8/9/2025 | 17/6/2026 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that… | |
| Analizada | Alta (7.8) | 0.18% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.25% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.26% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Media (5.5) | 0.24% | — | Foxit PDF EditorFoxit PDF Reader | 2/9/2025 | 17/6/2026 | Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Media (4.3) | 0.13% | — | AJ Square INC RSS ReaderAI | 23/8/2025 | 17/6/2026 | The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.6. This is due to missing or incorrect nonce validation on the 'sil_rss_edit_page' page. This makes it possible for unauthenticated attackers to delete RSS feeds via a forged request… | |
| Aplazada | Alta (8.4) | 0.34% | 💥 Exploit | Foxit PDF ReaderAI | 20/8/2025 | 16/6/2026 | Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the… | |
| Aplazada | Alta (8.4) | 0.38% | 💥 Exploit | Foxit PDF ReaderAI | 20/8/2025 | 16/6/2026 | Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content to write arbitrary files anywhere on disk. By embedding a malicious PDF that calls this API, an attacker can drop executables or scripts into privileged folders, leading to code execution the next… | |
| Modificada | Alta (8.8) | 0.60% | — | Foxit PDF Reader | 13/8/2025 | 17/6/2026 | A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick… | |
| Aplazada | Crítica (9.4) | 1.4% | 💥 Exploit | Foxit ReaderAIFoxit Reader PluginAI | 5/8/2025 | 16/6/2026 | Foxit Reader versions through 5.4.5.0114, including the bundled Foxit Reader Plugin 2.2.1.530, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a remote host, an overly long query string in the URL can overflow a buffer, allowing remote… | |
| Aplazada | Crítica (9.8) | 1.2% | — | UI Unifi Access Reader PROAIUI Unifi Access G2 Reader PROAIUI Unifi Access G3 Reader PROAIUI Unifi Access IntercomAI+2 | 4/8/2025 | 17/6/2026 | An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro… | |
| Analizada | Media (5.3) | 0.34% | — | Sequoia-pgp Buffered-reader | 28/7/2025 | 17/6/2026 | The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic. | |
| Aplazada | Media (4.3) | 0.19% | — | Gallagher T-series ReaderAI | 10/7/2025 | 17/6/2026 | Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (distributed in… | |
| Aplazada | Media (5.6) | 0.18% | — | ChmlibAISumatrapdfreader SumatrapdfAI | 4/7/2025 | 17/6/2026 | CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes. | |
| Analizada | Baja (2.4) | 0.15% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | |
| Analizada | Media (6.8) | 0.25% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | |
| Analizada | Media (5.5) | 0.41% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 10/6/2025 | 17/6/2026 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in… | |
| Analizada | Media (5.5) | 0.34% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 10/6/2025 | 17/6/2026 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue… | |
| Analizada | Media (5.5) | 0.20% | — | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe AcrobatAdobe Acrobat Reader | 10/6/2025 | 17/6/2026 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information. Exploitation of this issue does not… |