Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.48% | — | Jfrog Artifactory | 3/10/2023 | 17/6/2026 | JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body. | |
| Modificada | Media (5.4) | 0.51% | — | Wpartisan Wordpress Charts | 20/9/2023 | 17/6/2026 | The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Partition Wizard | 19/9/2023 | 17/6/2026 | MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Partition Wizard | 19/9/2023 | 17/6/2026 | MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | |
| Modificada | Alta (8.8) | 6.0% | 💥 PoC | Artifex GhostscriptFedoraproject Fedora | 18/9/2023 | 17/6/2026 | In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs… | |
| Modificada | Media (5.5) | 0.34% | — | Artifex GhostscriptRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 23/8/2023 | 17/6/2026 | A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. | |
| Modificada | Media (5.5) | 0.31% | — | Artifex Mupdf | 22/8/2023 | 17/6/2026 | A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information. | |
| Modificada | Media (5.5) | 0.51% | — | Artifex Mupdf | 22/8/2023 | 17/6/2026 | A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file. | |
| Modificada | Alta (7.8) | 0.81% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document. | |
| Modificada | Media (5.5) | 0.70% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file. | |
| Modificada | Media (4.8) | 0.37% | — | Artiss Plugins List | 18/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Artiss Plugins List plugin <= 2.5 versions. | |
| Modificada | Media (6.5) | 0.67% | — | Jenkins Maven Artifact Choicelistprovider (nexus) | 16/8/2023 | 17/6/2026 | Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Modificada | Media (4.8) | 0.37% | — | Icontrolwp Article Directory Redux | 14/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <= 1.0.2 versions. | |
| Modificada | Media (5.5) | 0.32% | — | Artifex Ghostscript | 1/8/2023 | 17/6/2026 | An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format. | |
| Modificada | Media (5.5) | 0.43% | — | Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 1/8/2023 | 23/6/2026 | A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs. | |
| Modificada | Media (6.1) | 0.32% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /change-language/de_DE of the component Base64 Encoding Handler. The manipulation of the argument redirectTo leads to open redirect. The attack may be launched… | |
| Modificada | Media (5.4) | 0.36% | — | Livelyworks Articart | 16/7/2023 | 17/6/2026 | A vulnerability has been found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /items/search. The manipulation of the argument search_term leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234229… | |
| Modificada | Alta (7.5) | 0.71% | — | Artifex Mujs | 7/7/2023 | 17/6/2026 | In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service. | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Artifex GhostscriptDebian LinuxFedoraproject Fedora | 25/6/2023 | 28/8/2026 | Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). | |
| Modificada | Media (6.1) | 0.38% | — | Artistscope Copysafe WEB Protection | 26/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ArtistScope CopySafe Web Protection plugin <= 3.13 versions. | |
| Modificada | Media (5.3) | 2.2% | 💥 Exploit | Evilmartians Imgproxy | 8/5/2023 | 17/6/2026 | imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 0.81% | — | Artifex Mujs | 17/4/2023 | 17/6/2026 | Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d. | |
| Modificada | Media (4.8) | 0.47% | — | Article Directory Project Article Directory | 10/4/2023 | 17/6/2026 | The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts. | |
| Modificada | Crítica (9.8) | 6.3% | — | Artifex GhostscriptDebian Linux | 31/3/2023 | 17/6/2026 | In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an… |