Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5) | 0.11% | — | Gpac Project Mp4boxAI | 3/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Modificada | Media (5.7) | 0.46% | — | Opto22 Softpac Project | 14/5/2020 | 17/6/2026 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious files. | |
| Modificada | Media (6.5) | 0.51% | — | Opto22 Softpac Project | 14/5/2020 | 17/6/2026 | Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbitrary file write access with system access. | |
| Modificada | Crítica (9.8) | 1.2% | — | Opto22 Softpac Project | 14/5/2020 | 17/6/2026 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely. | |
| Modificada | Alta (8.8) | 1.7% | — | Opto22 Softpac Project | 14/5/2020 | 17/6/2026 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts. | |
| Modificada | Crítica (9.1) | 1.1% | — | Opto22 Softpac Project | 14/5/2020 | 17/6/2026 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with network access to control the SoftPACAgent service including updating SoftPAC firmware, starting or stopping service,… | |
| Modificada | Crítica (9.8) | 5.3% | — | Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project | 10/5/2019 | 17/6/2026 | A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were… | |
| Modificada | Alta (7.8) | 2.7% | — | Opto22 OptodatalinkOpto22 OptoopcserverOpto22 PAC DisplayOpto22 PAC Project | 25/3/2019 | 17/6/2026 | A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC… | |
| Modificada | Alta (7.8) | 1.4% | — | Gpac Project GpacDebian LinuxCanonical Ubuntu Linux | 6/2/2019 | 17/6/2026 | In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking. | |
| Modificada | Alta (7.8) | 1.5% | — | Gpac Project GpacDebian LinuxCanonical Ubuntu Linux | 6/2/2019 | 17/6/2026 | GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames. | |
| Modificada | Alta (7.8) | 1.5% | — | Gpac Project GpacDebian LinuxCanonical Ubuntu Linux | 6/2/2019 | 17/6/2026 | GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a. | |
| Modificada | Alta (7.8) | 1.1% | — | Gpac Project GpacCanonical Ubuntu Linux | 6/3/2018 | 17/6/2026 | GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE. | |
| Modificada | Media (6.8) | 0.64% | — | Opac Project Opac | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors. |