Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.32%—Artifex GhostscriptDebian Linux10/11/202417/6/2026
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
ModificadaAlta (7.8)0.36%—Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+110/11/202417/6/2026
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
AplazadaAlta (8.7)0.17%—Nvidia Connectx Host FirmwareAINvidia Bluefield DPUAI1/11/202417/6/2026
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.
AnalizadaMedia (5.9)1.0%💥 PoCNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+827/10/202417/6/2026
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
AnalizadaAlta (7.1)0.30%—Echostar Fusion5/9/202417/6/2026
Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.
AnalizadaMedia (4.1)0.20%—Echostar Fusion5/9/202417/6/2026
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
AnalizadaMedia (6.5)0.32%—Ghost20/8/202417/6/2026
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
ModificadaAlta (8.6)1.8%💥 ExploitWpplugins Hide MY WP Ghost23/7/202417/6/2026
The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
AnalizadaMedia (5.9)0.80%💥 ExploitKibokolabs Hostel13/7/202417/6/2026
The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaAlta (8.8)1.4%—Artifex Ghostscript3/7/202417/6/2026
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this…
AnalizadaMedia (6.3)0.52%—Artifex Ghostscript3/7/202417/6/2026
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.
AnalizadaMedia (5.3)0.45%—Artifex Ghostscript3/7/202417/6/2026
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
AnalizadaAlta (7.5)1.1%—Artifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
AnalizadaMedia (6.3)28%💥 ExploitArtifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
AnalizadaMedia (5.4)0.72%—Artifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
ModificadaAlta (8.8)1.4%—Artifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
ModificadaBaja (3.3)0.38%—Artifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
ModificadaAlta (8.8)0.91%—Artifex Ghostscript3/7/202417/6/2026
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
AnalizadaCrítica (9.1)0.77%—Ghost16/6/202417/6/2026
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
AplazadaMedia (6.5)0.60%—Kape CyberghostvpnAI11/6/202417/6/2026
An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it.
ModificadaCrítica (9.8)1.0%💥 PoCWeb-shop-host Startklar Elmentor Addons6/6/202417/6/2026
The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information,…
AnalizadaMedia (5.3)0.48%—Wpplugins Hide MY WP Ghost4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
AnalizadaAlta (8.8)0.73%—Ghost22/5/202417/6/2026
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
AplazadaMedia (4.3)0.21%—Kibokolabs HostelAI14/5/202417/6/2026
The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can…
AplazadaAlta (7.5)0.72%—GhostAI14/5/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.
Orbitaley — Vulnerabilidades