Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5)0.11%—Gpac Project Mp4boxAI3/6/202622/7/2026
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
AplazadaMedia (5.5)0.13%—Gpac Project Mp4boxAI1/6/202622/7/2026
A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.
AplazadaMedia (5.5)0.13%—Gpac Project Mp4boxAI1/6/202622/7/2026
A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.
AplazadaMedia (5.5)0.14%—Gpac Project Mp4boxAI1/6/202622/7/2026
A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
AplazadaMedia (5.5)0.14%—Gpac Project Mp4boxAI1/6/202622/7/2026
A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
AplazadaMedia (5.5)0.14%—Gpac Project Mp4boxAI1/6/202622/7/2026
A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
ModificadaMedia (5.7)0.46%—Opto22 Softpac Project14/5/202017/6/2026
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files.
ModificadaMedia (6.5)0.51%—Opto22 Softpac Project14/5/202017/6/2026
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access.
ModificadaCrítica (9.8)1.2%—Opto22 Softpac Project14/5/202017/6/2026
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.
ModificadaAlta (8.8)1.7%—Opto22 Softpac Project14/5/202017/6/2026
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts.
ModificadaCrítica (9.1)1.1%—Opto22 Softpac Project14/5/202017/6/2026
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAgent service including updating SoftPAC firmware, starting or stopping service,…
ModificadaCrítica (9.8)5.3%—Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project10/5/201917/6/2026
A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were…
ModificadaAlta (7.8)2.7%—Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project25/3/201917/6/2026
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC…
ModificadaAlta (7.8)1.4%—Gpac Project GpacDebian LinuxCanonical Ubuntu Linux6/2/201917/6/2026
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
ModificadaAlta (7.8)1.5%—Gpac Project GpacDebian LinuxCanonical Ubuntu Linux6/2/201917/6/2026
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
ModificadaAlta (7.8)1.5%—Gpac Project GpacDebian LinuxCanonical Ubuntu Linux6/2/201917/6/2026
GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
ModificadaAlta (7.8)1.1%—Gpac Project GpacCanonical Ubuntu Linux6/3/201817/6/2026
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
ModificadaMedia (6.8)0.64%—Opac Project Opac21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors.