Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.
ModificadaAlta (8.4)0.42%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+125/11/202517/6/2026
A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.
ModificadaAlta (8.4)0.34%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+125/11/202517/6/2026
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+118/8/202517/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the…
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+118/8/202517/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in…
AnalizadaAlta (8.4)0.16%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+118/8/202517/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the…
AnalizadaAlta (8.4)0.16%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+118/8/202517/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the…
AnalizadaAlta (8.8)0.83%—Ashlar Lithium3/5/202417/6/2026
Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Lithium. User interaction is required to exploit this vulnerability in that the target must visit a malicious page…
AnalizadaAlta (7.8)0.20%—Ashlar CobaltAshlar GraphiteAshlar XenonAshlar Argon+126/10/202317/6/2026
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of…
ModificadaMedia (4.4)0.33%—Khoros Lithium Forum28/6/202217/6/2026
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has…
ModificadaMedia (6.4)2.4%—Lithium CMS6/11/200616/6/2026
Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and…
ModificadaMedia (5)2.8%—Lithium Software Lithium II MOD2/9/200516/6/2026
Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.