Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1720 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.61%—Samsung Magicinfo 9 Server23/7/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0
AplazadaAlta (8.4)0.48%💥 ExploitHeroes OF Might AND Magic III CompleteAIHeroes OF Might AND Magic HD MODAI16/7/202517/6/2026
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow,…
ModificadaCrítica (9.8)0.91%—Imagemagick14/7/202517/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address…
ModificadaAlta (7.5)0.52%—Imagemagick14/7/202517/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the…
AnalizadaAlta (7.5)0.78%—Imagemagick14/7/202517/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
ModificadaCrítica (9.8)0.68%—Imagemagick14/7/202517/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings…
ModificadaMedia (5.4)0.25%—Pwrplugins Magic Buttons FOR Elementor2/7/202517/6/2026
The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'icon' user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (5.4)0.24%—Pwrplugins Magic Buttons FOR Elementor2/7/202517/6/2026
The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'text' user supplied attribute. This makes it possible for authenticated…
AplazadaMedia (4.8)0.15%—Blackmagicdesign Davinci ResolveAI29/5/202517/6/2026
Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,…
ModificadaCrítica (9.8)1.4%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
ModificadaCrítica (9.1)1.4%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,…
ModificadaAlta (7.5)0.68%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
ModificadaCrítica (9.8)1.3%💥 PoCEmagicone Store Manager FOR Woocommerce24/5/202517/6/2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AplazadaAlta (7.1)0.54%—H3C Magic R200gAI20/5/202517/6/2026
A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of the file…
AplazadaAlta (8.5)0.42%—Lambertgroup Magic CarouselAI16/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress magic-carousel allows SQL Injection.This issue affects Magic Responsive Slider and Carousel WordPress: from n/a through < 1.6.
AnalizadaMedia (4.8)0.31%—Metagauss Registrationmagic15/5/202517/6/2026
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaAlta (7.2)2.2%—Orangelab Imagemagick Engine15/5/202517/6/2026
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the "cli_path" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.
AnalizadaCrítica (9.8)24%⚠ Explotación activa💥 ExploitSamsung Magicinfo 9 Server13/5/202517/6/2026
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
AnalizadaMedia (5.3)0.41%—Imagemagick23/4/202517/6/2026
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
AnalizadaAlta (7.5)0.58%—ImagemagickDebian Linux23/4/202517/6/2026
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
AplazadaCrítica (9.3)0.37%—Matthewrubin Local MagicAI17/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic local-magic allows SQL Injection.This issue affects Local Magic: from n/a through <= 2.9.0.
AnalizadaAlta (8.6)1.6%—H3C Magic Nx15 FirmwareH3C Magic Nx30 PRO FirmwareH3C Magic Nx400 FirmwareH3C Magic R3010 Firmware+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler.…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI14/4/202517/6/2026
A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability affects the function FCGI_WizardProtoProcess of the file /api/wizard/setsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command…