Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.2%—Artifex MujsDebian LinuxFedoraproject Fedora18/5/202217/6/2026
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
ModificadaAlta (8.8)2.1%—Jfrog Artifactory16/5/202217/6/2026
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized…
ModificadaCrítica (9.8)2.6%—Articatech Artica Proxy5/5/202217/6/2026
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
ModificadaAlta (8.1)1.4%—Articatech WEB Proxy25/4/202217/6/2026
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.
ModificadaAlta (7.8)1.2%—Artifex GhostscriptDebian Linux25/4/202217/6/2026
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
ModificadaAlta (7.8)0.84%—Artifex Ghostpcl14/4/202217/6/2026
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been…
ModificadaBaja (2.7)0.65%—Jfrog Artifactory2/3/202217/6/2026
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
ModificadaMedia (5.4)0.63%—Jfrog Artifactory2/3/202217/6/2026
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
ModificadaCrítica (9.9)84%—Artifex GhostscriptFedoraproject Fedora16/2/202217/6/2026
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this…
ModificadaCrítica (9.8)1.4%—Artifex Mujs14/2/202217/6/2026
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptDebian Linux1/1/202217/6/2026
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
ModificadaMedia (5.5)1.4%—Artifex GhostscriptDebian Linux31/12/20217/10/2026
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
ModificadaAlta (8.8)1.00%—Jfrog Artifactory20/12/202117/6/2026
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.
ModificadaMedia (5.4)0.52%—Artica Pandora FMS3/11/20219/7/2026
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
ModificadaMedia (6.7)0.32%—Artica Pandora FMS3/11/20219/7/2026
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.
ModificadaMedia (6.1)0.59%—Artica Integria IMS7/10/202117/6/2026
Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).
ModificadaCrítica (9.8)1.1%—Artica Integria IMS7/10/202117/6/2026
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.
ModificadaCrítica (9.8)2.3%—Artica Integria IMS7/10/202117/6/2026
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
ModificadaMedia (6.8)0.56%—Email Artillery Project Email Artillery13/9/202117/6/2026
The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the…
ModificadaCrítica (9.8)2.7%—Artixlinux Opensysusers25/8/202117/6/2026
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.
ModificadaMedia (5.5)1.3%—Artifex MupdfFedoraproject Fedora21/7/202117/6/2026
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
ModificadaMedia (5.5)1.0%—Artifex MupdfDebian Linux21/7/202117/6/2026
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
ModificadaAlta (7.5)1.6%—Artifex Mujs13/7/202117/6/2026
Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)1.6%—Artifex Mujs13/7/202117/6/2026
Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.
ModificadaMedia (5.9)0.92%—Artica Pandora FMS30/6/202117/6/2026
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
Orbitaley — Vulnerabilidades