Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1700 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.46% | — | H3C Magic M Device M2v100r006AI | 12/9/2025 | 17/6/2026 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password | |
| Modificada | Crítica (9.8) | 0.29% | — | Imagemagick | 5/9/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum +… | |
| Analizada | Media (5.3) | 0.25% | — | Samsung Magician | 2/9/2025 | 17/6/2026 | An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process. | |
| Modificada | Alta (8.8) | 0.84% | — | Imagemagick | 26/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer… | |
| Modificada | Alta (8.8) | 4.5% | — | Imagemagick | 26/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An… | |
| Modificada | Alta (7.5) | 0.91% | — | Imagemagick | 26/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions,… | |
| Aplazada | Media (6.5) | 0.18% | — | Noor Alam Magical Posts DisplayAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display magical-posts-display allows DOM-Based XSS.This issue affects Magical Posts Display: from n/a through <= 1.2.52. | |
| Analizada | Media (5.3) | 0.41% | — | Imagemagick | 13/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a… | |
| Modificada | Alta (7.8) | 0.96% | — | Imagemagick | 13/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and… | |
| Analizada | Media (5.5) | 0.26% | — | Imagemagick | 13/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to… | |
| Analizada | Media (4.3) | 0.55% | — | Imagemagick | 13/8/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to… | |
| Aplazada | Media (6.4) | 0.23% | — | Magic Edge LiteAI | 2/8/2025 | 17/6/2026 | The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.23% | — | Wpthemespace Magical Addons FOR ElementorAI | 29/7/2025 | 17/6/2026 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Crítica (9.8) | 0.55% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.54% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 24% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.39% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.65% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.59% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.63% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.46% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 12% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.60% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |