Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.18% | — | Gnome EvinceAITUG TEX LiveAI | 21/7/2026 | 23/7/2026 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX… | |
| Pendiente de análisis | Media (6.5) | 0.15% | — | Cert VinceAI | 7/5/2026 | 17/6/2026 | VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates. | |
| Aplazada | Media (6.5) | 0.17% | — | Vincent Boiardt Easy Flash EmbedAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Easy Flash Embed easy-flash-embed allows Stored XSS.This issue affects Easy Flash Embed: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.23% | — | Rally Vincent BauernregelnAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rally Vincent Bauernregeln bauernregeln allows Reflected XSS.This issue affects Bauernregeln: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Vincent LOY YET Another CountdownAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Loy Yet Another Countdown yacp allows DOM-Based XSS.This issue affects Yet Another Countdown: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.41% | — | Vincent Mimoun-prat WP Pt-viewerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Prat WP PT-Viewer wp-ptviewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through <= 2.0.2. | |
| Modificada | Media (6.5) | 0.18% | — | Cert Vince | 28/10/2024 | 17/6/2026 | VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. | |
| Modificada | Alta (8.8) | 0.51% | — | Jonvincentmendoza Dynamic Elementor Addons | 18/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ramjon27 Dynamic Elementor Addons dynamic-elementor-addons allows PHP Local File Inclusion.This issue affects Dynamic Elementor Addons: from n/a through <= 1.0.0. | |
| Modificada | Media (4.9) | 0.44% | — | Cert Vince | 14/10/2024 | 17/6/2026 | A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to… | |
| Modificada | Alta (8.8) | 1.3% | — | Cert Vince | 26/10/2022 | 17/6/2026 | A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is accessed. | |
| Modificada | Media (5.4) | 0.39% | — | Cert Vince | 10/10/2022 | 17/6/2026 | An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field. | |
| Modificada | Media (5.4) | 0.41% | — | Cert Vince | 10/10/2022 | 17/6/2026 | An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field. | |
| Modificada | Media (6.1) | 0.57% | — | Cert Vince | 16/8/2022 | 17/6/2026 | An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be redirected to a malicious site that is designed… | |
| Modificada | Media (5.5) | 1.1% | — | Gnome EvinceDebian LinuxOpensuseRedhat Enterprise Linux | 1/11/2019 | 16/6/2026 | evince is missing a check on number of pages which can lead to a segmentation fault | |
| Modificada | Alta (7.8) | 2.1% | — | Gnome EvinceCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/7/2019 | 17/6/2026 | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and… | |
| Modificada | Media (5.5) | 1.4% | — | Gnome EvinceCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+5 | 22/4/2019 | 17/6/2026 | The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. | |
| Modificada | Alta (7.8) | 0.30% | — | Sophos Invincea-x | 24/4/2018 | 17/6/2026 | An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to… | |
| Modificada | Alta (7.8) | 0.58% | — | Sophos Invincea Dell Protected Workspace | 24/4/2018 | 17/6/2026 | Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product. | |
| Modificada | Alta (7.8) | 1.4% | — | Gnome Evince | 27/11/2017 | 17/6/2026 | Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. | |
| Modificada | Alta (7.8) | 51% | — | Gnome EvinceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 5/9/2017 | 17/6/2026 | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the… | |
| Modificada | Media (6.8) | 3.4% | — | Gnome EvinceT1libTetex | 19/11/2012 | 16/6/2026 | Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted… | |
| Modificada | Media (6.8) | 4.2% | — | Gnome EvinceT1libTetex | 19/11/2012 | 16/6/2026 | Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different… | |
| Modificada | Media (4.3) | 1.2% | — | Jesse Vincent Extension\ | 15/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the Extension::MobileUI extension before 1.02 for Best Practical Solutions RT 3.8.x and in Best Practical Solutions RT before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Devincentiis Gazie | 21/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password. | |
| Modificada | Alta (7.6) | 6.0% | — | Redhat Evince | 7/1/2011 | 16/6/2026 | Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. |