Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Is-daouda Is-engineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4. | |
| Aplazada | Alta (7.5) | 0.30% | — | IS Daouda IS EngineAI | 27/1/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4. | |
| Analizada | Media (6.9) | 0.69% | — | Riskengine Radar | 18/10/2024 | 17/6/2026 | A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../ leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 0.71% | — | Riskengine Radar | 18/10/2024 | 17/6/2026 | A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.8) | 2.0% | — | Esri Arcgis EngineEsri Arcgis PROEsri ArcmapEsri Arcreader | 25/3/2021 | 17/6/2026 | Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user. | |
| Modificada | Alta (7.8) | 2.4% | — | Esri Arcgis EngineEsri Arcgis PROEsri ArcmapEsri Arcreader | 25/3/2021 | 17/6/2026 | Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code execution in the context of the current user. | |
| Modificada | Alta (7.8) | 1.5% | — | Esri Arcgis EngineEsri Arcgis PROEsri ArcmapEsri Arcreader | 25/3/2021 | 17/6/2026 | A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user. | |
| Modificada | Media (5.1) | 1.7% | — | Broadcom Etrust AntivirusBroadcom Etrust Antivirus Iris Engine | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of (1) eTrust-Iris and (2) eTrust-Vet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip,… |