Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1700 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.57% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Analizada | Crítica (9.8) | 0.47% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Alta (8.8) | 10% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.50% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Alta (8.8) | 9.0% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Samsung Magicinfo 9 Server | 23/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0 | |
| Aplazada | Alta (8.4) | 0.48% | 💥 Exploit | Heroes OF Might AND Magic III CompleteAIHeroes OF Might AND Magic HD MODAI | 16/7/2025 | 17/6/2026 | A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow,… | |
| Modificada | Crítica (9.8) | 0.91% | — | Imagemagick | 14/7/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address… | |
| Modificada | Alta (7.5) | 0.52% | — | Imagemagick | 14/7/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the… | |
| Analizada | Alta (7.5) | 0.78% | — | Imagemagick | 14/7/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue. | |
| Modificada | Crítica (9.8) | 0.68% | — | Imagemagick | 14/7/2025 | 17/6/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings… | |
| Modificada | Media (5.4) | 0.25% | — | Pwrplugins Magic Buttons FOR Elementor | 2/7/2025 | 17/6/2026 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'icon' user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.24% | — | Pwrplugins Magic Buttons FOR Elementor | 2/7/2025 | 17/6/2026 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'text' user supplied attribute. This makes it possible for authenticated… | |
| Aplazada | Media (4.8) | 0.15% | — | Blackmagicdesign Davinci ResolveAI | 29/5/2025 | 17/6/2026 | Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,… | |
| Modificada | Crítica (9.8) | 1.4% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Modificada | Crítica (9.1) | 1.4% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Modificada | Alta (7.5) | 0.68% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Modificada | Crítica (9.8) | 1.3% | 💥 PoC | Emagicone Store Manager FOR Woocommerce | 24/5/2025 | 17/6/2026 | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Alta (7.1) | 0.54% | — | H3C Magic R200gAI | 20/5/2025 | 17/6/2026 | A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of the file… | |
| Aplazada | Alta (8.5) | 0.42% | — | Lambertgroup Magic CarouselAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress magic-carousel allows SQL Injection.This issue affects Magic Responsive Slider and Carousel WordPress: from n/a through < 1.6. | |
| Analizada | Media (4.8) | 0.31% | — | Metagauss Registrationmagic | 15/5/2025 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (7.2) | 2.2% | — | Orangelab Imagemagick Engine | 15/5/2025 | 17/6/2026 | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution. | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa💥 Exploit | Samsung Magicinfo 9 Server | 13/5/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. | |
| Analizada | Media (5.3) | 0.41% | — | Imagemagick | 23/4/2025 | 17/6/2026 | In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). | |
| Analizada | Alta (7.5) | 0.58% | — | ImagemagickDebian Linux | 23/4/2025 | 17/6/2026 | In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. |