Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Articlecms Project Articlecms | 13/5/2021 | 17/6/2026 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. | |
| Modificada | Crítica (9.8) | 1.3% | — | Articlecms Project Articlecms | 13/5/2021 | 17/6/2026 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code. | |
| Modificada | Media (6.5) | 2.6% | — | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user. | |
| Modificada | Crítica (9.8) | 13% | 💥 PoC | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass. | |
| Modificada | Crítica (9.8) | 2.5% | — | Artica Pandora FMS | 7/5/2021 | 17/6/2026 | Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. | |
| Modificada | Media (5.4) | 9.4% | — | Jenkins Artifact Repository Parameter | 24/2/2021 | 17/6/2026 | Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Media (5.5) | 50% | — | Artifex MupdfFedoraproject FedoraDebian Linux | 23/2/2021 | 17/6/2026 | A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. | |
| Modificada | Alta (7.8) | 0.96% | — | Artifex Mupdf | 9/12/2020 | 17/6/2026 | A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer. | |
| Modificada | Alta (7.8) | 0.43% | — | KDE Partition Manager | 26/10/2020 | 17/6/2026 | An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker on the local machine can replace /etc/fstab, and execute mount and other partitioning related commands, while KDE… | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Jfrog Artifactory | 12/10/2020 | 17/6/2026 | Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0. | |
| Modificada | Media (5.5) | 1.0% | — | Artifex MupdfDebian LinuxFedoraproject Fedora | 2/10/2020 | 17/6/2026 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service. | |
| Modificada | Crítica (9.8) | 2.1% | — | Artica Pandora FMS | 2/10/2020 | 17/6/2026 | Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter. | |
| Modificada | Media (5.5) | 0.45% | — | Artifex GhostscriptRedhat Enterprise Linux | 3/9/2020 | 17/6/2026 | A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service. | |
| Modificada | Alta (7.8) | 0.83% | — | Artifex Mujs | 13/8/2020 | 17/6/2026 | Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.3% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Analizada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51. | |
| Modificada | Alta (7.8) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. |