Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.15%—Blackmagicdesign Davinci ResolveAI29/5/202517/6/2026
Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,…
AplazadaAlta (8.4)0.21%—Davinci ResolveAI28/2/202517/6/2026
DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit…
ModificadaMedia (6.5)0.63%—Davinci Project Davinci17/5/202317/6/2026
In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.
ModificadaAlta (8.8)0.60%—Davinci Project Davinci17/5/202317/6/2026
davinci 0.3.0-rc is vulnerable to Server-side request forgery (SSRF).
ModificadaCrítica (9.8)0.74%—Davinci Project Davinci27/2/202317/6/2026
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
ModificadaCrítica (9.8)18%—Blackmagicdesign Davinci Resolve22/12/202117/6/2026
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction of the object that owns it, the uninitialized member will be…
ModificadaCrítica (9.8)16%—Blackmagicdesign Davinci Resolve22/12/202117/6/2026
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards…
ModificadaBaja (2.1)0.32%—Royal Davinci1/1/199916/6/2026
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.