Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.32% | — | Artifex GhostscriptDebian Linux | 10/11/2024 | 17/6/2026 | An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values). | |
| Modificada | Alta (7.8) | 0.36% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. | |
| Aplazada | Alta (8.7) | 0.17% | — | Nvidia Connectx Host FirmwareAINvidia Bluefield DPUAI | 1/11/2024 | 17/6/2026 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure. | |
| Analizada | Media (5.9) | 1.0% | 💥 PoC | Netapp Active IQ Unified ManagerNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage NodeNetapp Windows Host Utilities+8 | 27/10/2024 | 17/6/2026 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | |
| Analizada | Alta (7.1) | 0.30% | — | Echostar Fusion | 5/9/2024 | 17/6/2026 | Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data. | |
| Analizada | Media (4.1) | 0.20% | — | Echostar Fusion | 5/9/2024 | 17/6/2026 | Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data. | |
| Analizada | Media (6.5) | 0.32% | — | Ghost | 20/8/2024 | 17/6/2026 | Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue. | |
| Modificada | Alta (8.6) | 1.8% | 💥 Exploit | Wpplugins Hide MY WP Ghost | 23/7/2024 | 17/6/2026 | The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. | |
| Analizada | Media (5.9) | 0.80% | 💥 Exploit | Kibokolabs Hostel | 13/7/2024 | 17/6/2026 | The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (8.8) | 1.4% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this… | |
| Analizada | Media (6.3) | 0.52% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted. | |
| Analizada | Media (5.3) | 0.45% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename. | |
| Analizada | Alta (7.5) | 1.1% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd. | |
| Analizada | Media (6.3) | 28% | 💥 Exploit | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. | |
| Analizada | Media (5.4) | 0.72% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters. | |
| Modificada | Alta (8.8) | 1.4% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle. | |
| Modificada | Baja (3.3) | 0.38% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc. | |
| Modificada | Alta (8.8) | 0.91% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name. | |
| Analizada | Crítica (9.1) | 0.77% | — | Ghost | 16/6/2024 | 17/6/2026 | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers. | |
| Aplazada | Media (6.5) | 0.60% | — | Kape CyberghostvpnAI | 11/6/2024 | 17/6/2026 | An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while the process is still open, and can be obtained by dumping the process memory and parsing it. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Web-shop-host Startklar Elmentor Addons | 6/6/2024 | 17/6/2026 | The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information,… | |
| Analizada | Media (5.3) | 0.48% | — | Wpplugins Hide MY WP Ghost | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25. | |
| Analizada | Alta (8.8) | 0.73% | — | Ghost | 22/5/2024 | 17/6/2026 | Ghost before 5.82.0 allows CSV Injection during a member CSV export. | |
| Aplazada | Media (4.3) | 0.21% | — | Kibokolabs HostelAI | 14/5/2024 | 17/6/2026 | The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can… | |
| Aplazada | Alta (7.5) | 0.72% | — | GhostAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0. |