Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.2% | — | Artifex MujsDebian LinuxFedoraproject Fedora | 18/5/2022 | 17/6/2026 | compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413. | |
| Modificada | Alta (8.8) | 2.1% | — | Jfrog Artifactory | 16/5/2022 | 17/6/2026 | JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized… | |
| Modificada | Crítica (9.8) | 2.6% | — | Articatech Artica Proxy | 5/5/2022 | 17/6/2026 | A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | |
| Modificada | Alta (8.1) | 1.4% | — | Articatech WEB Proxy | 25/4/2022 | 17/6/2026 | There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi. | |
| Modificada | Alta (7.8) | 1.2% | — | Artifex GhostscriptDebian Linux | 25/4/2022 | 17/6/2026 | Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839. | |
| Modificada | Alta (7.8) | 0.84% | — | Artifex Ghostpcl | 14/4/2022 | 17/6/2026 | A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been… | |
| Modificada | Baja (2.7) | 0.65% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation. | |
| Modificada | Media (5.4) | 0.63% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session. | |
| Modificada | Crítica (9.9) | 84% | — | Artifex GhostscriptFedoraproject Fedora | 16/2/2022 | 17/6/2026 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this… | |
| Modificada | Crítica (9.8) | 1.4% | — | Artifex Mujs | 14/2/2022 | 17/6/2026 | Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 1/1/2022 | 17/6/2026 | Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp). | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 31/12/2021 | 7/10/2026 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). | |
| Modificada | Alta (8.8) | 1.00% | — | Jfrog Artifactory | 20/12/2021 | 17/6/2026 | JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query. | |
| Modificada | Media (5.4) | 0.52% | — | Artica Pandora FMS | 3/11/2021 | 9/7/2026 | Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name. | |
| Modificada | Media (6.7) | 0.32% | — | Artica Pandora FMS | 3/11/2021 | 9/7/2026 | With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request. | |
| Modificada | Media (6.1) | 0.59% | — | Artica Integria IMS | 7/10/2021 | 17/6/2026 | Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS). | |
| Modificada | Crítica (9.8) | 1.1% | — | Artica Integria IMS | 7/10/2021 | 17/6/2026 | Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords. | |
| Modificada | Crítica (9.8) | 2.3% | — | Artica Integria IMS | 7/10/2021 | 17/6/2026 | Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability. | |
| Modificada | Media (6.8) | 0.56% | — | Email Artillery Project Email Artillery | 13/9/2021 | 17/6/2026 | The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the… | |
| Modificada | Crítica (9.8) | 2.7% | — | Artixlinux Opensysusers | 25/8/2021 | 17/6/2026 | opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that. | |
| Modificada | Media (5.5) | 1.3% | — | Artifex MupdfFedoraproject Fedora | 21/7/2021 | 17/6/2026 | MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input. | |
| Modificada | Media (5.5) | 1.0% | — | Artifex MupdfDebian Linux | 21/7/2021 | 17/6/2026 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | Artifex Mujs | 13/7/2021 | 17/6/2026 | Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | Artifex Mujs | 13/7/2021 | 17/6/2026 | Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service. | |
| Modificada | Media (5.9) | 0.92% | — | Artica Pandora FMS | 30/6/2021 | 17/6/2026 | In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access. |