Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.6%💥 ExploitEvilmartians Imgproxy19/3/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
ModificadaMedia (4.3)0.23%—Xnau Participants Database28/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update.
ModificadaMedia (6.1)1.2%💥 ExploitArtisanworkshop Japanized FOR Woocommerce21/2/202317/6/2026
The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)2.1%💥 PoCNosh Chartingsystem Project Nosh Chartingsystem1/2/202317/6/2026
NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting.
ModificadaMedia (5.4)0.57%—Nosh Chartingsystem Project Nosh Chartingsystem29/1/202317/6/2026
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.
ModificadaMedia (6.1)0.52%—01-scripts 01-artikelsystem9/1/202317/6/2026
A vulnerability was found in 01-Scripts 01-Artikelsystem. It has been classified as problematic. Affected is an unknown function of the file 01article.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to launch the attack remotely. The patch is identified as…
ModificadaCrítica (9.8)0.63%—Jfrog Artifactory8/1/202317/6/2026
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
ModificadaAlta (8.8)2.5%💥 PoCArtifex MujsDebian LinuxFedoraproject Fedora23/11/202217/6/2026
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
ModificadaMedia (5.5)0.24%—Artifex Mupdf26/8/202217/6/2026
A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.
ModificadaMedia (6.1)1.6%💥 ExploitArticatech Artica Proxy24/8/202217/6/2026
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
ModificadaAlta (7.1)0.46%—Artifex GhostscriptDebian Linux19/8/202217/6/2026
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
ModificadaMedia (6.1)0.42%—Artica Pandora FMS5/8/202217/6/2026
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.
ModificadaMedia (4.9)0.84%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaMedia (6.1)0.57%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before…
ModificadaAlta (8.8)0.36%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaCrítica (9)0.83%—Smartics27/6/202217/6/2026
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
ModificadaBaja (2.7)0.65%—Smartics27/6/202217/6/2026
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.
ModificadaMedia (4.9)0.81%—Smartics27/6/202217/6/2026
An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0.
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (5.5)1.4%—Artifex GhostscriptFedoraproject Fedora16/6/202217/6/2026
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64,…
ModificadaMedia (6.5)0.57%—Jfrog Artifactory23/5/202217/6/2026
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
ModificadaAlta (7.8)0.42%—Minitool Partition Wizard20/5/202217/6/2026
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
ModificadaMedia (4.9)0.54%—Jfrog Artifactory19/5/202217/6/2026
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
ModificadaMedia (5.5)1.1%—Artifex MujsDebian LinuxFedoraproject Fedora18/5/202217/6/2026
In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.