Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.91% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name. | |
| Analizada | Crítica (9.4) | 0.91% | — | Artica Pandora FMS | 10/6/2024 | 17/6/2026 | Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777. | |
| Analizada | Alta (8.7) | 0.93% | — | Artica Pandora FMS | 10/6/2024 | 17/6/2026 | OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777. | |
| Analizada | Alta (8.9) | 0.37% | — | Artica Pandora FMS | 10/6/2024 | 17/6/2026 | Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777. | |
| Analizada | Crítica (9.3) | 1.1% | — | Artica Pandora FMS | 10/6/2024 | 17/6/2026 | System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777. | |
| Aplazada | Media (5.4) | 0.31% | — | Martin Gibson WP Linkedin Auto PublishAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11. | |
| Modificada | Media (5.4) | 0.26% | — | Martintod Rotating Tweets | 6/6/2024 | 17/6/2026 | The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's' 'rotatingtweets' in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.20% | — | Elearningfreak Insert OR Embed Articulate Content | 4/6/2024 | 17/6/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page. | |
| Analizada | Media (5.4) | 0.94% | 💥 PoC | Elearningfreak Insert OR Embed Articulate Content | 4/6/2024 | 17/6/2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files | |
| Aplazada | Alta (7.3) | 0.30% | — | TOR ArtiAI | 17/5/2024 | 17/6/2026 | In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004. | |
| Aplazada | Media (6.2) | 0.19% | — | TOR ArtiAI | 17/5/2024 | 17/6/2026 | In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003. | |
| Aplazada | Media (6.4) | 0.27% | — | Jfrog ArtifactoryAIJfrog PlatformAI | 15/5/2024 | 17/6/2026 | A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email. | |
| Aplazada | Media (4.3) | 0.37% | — | Nico Martin Progressive Wordpress PWAAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13. | |
| Analizada | Media (6.8) | 0.79% | — | Jenkins Subversion Partial Release Manager | 2/5/2024 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. | |
| Aplazada | Crítica (9) | 0.67% | — | Jfrog ArtifactoryAI | 1/5/2024 | 17/6/2026 | An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled. | |
| Analizada | Media (5.5) | 0.33% | — | Artifex Ghostscript | 28/4/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard. | |
| Analizada | Media (4.3) | 0.41% | — | Jfrog Artifactory | 15/4/2024 | 17/6/2026 | JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments. | |
| Modificada | Media (6.5) | 0.45% | — | Davidartiss Code Embed | 21/3/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6. | |
| Analizada | Crítica (9.8) | 81% | 💥 Exploit | Articatech Artica Proxy | 21/3/2024 | 17/6/2026 | The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. | |
| Analizada | Alta (7.5) | 45% | 💥 Exploit | Articatech Artica Proxy | 21/3/2024 | 17/6/2026 | The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file… | |
| Modificada | Media (6.1) | 0.52% | — | Magenet Website Article Monetization | 20/3/2024 | 17/6/2026 | The Website Article Monetization By MageNet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'abp_auth_key' parameter in all versions up to, and including, 1.0.11 due to insufficient input sanitization and output escaping and a missing authorization check. This makes it possible for… | |
| Analizada | Crítica (9.1) | 0.85% | — | Artica Pandora FMS | 19/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776. | |
| Analizada | Crítica (9.8) | 0.45% | — | Artica Pandora FMS | 19/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This ulnerability allowed SQL injections to be made even if authentication failed.This issue affects Pandora FMS: from 700 through <776. | |
| Analizada | Media (6.4) | 0.34% | — | Artica Pandora FMS | 19/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776. | |
| Analizada | Media (6.5) | 0.39% | — | Artica Pandora FMS | 19/3/2024 | 17/6/2026 | : Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776. |