Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.5% | — | Itextpdf Itext | 1/2/2022 | 17/6/2026 | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Modificada | Media (6.5) | 1.6% | — | Itextpdf Itext | 1/2/2022 | 17/6/2026 | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Modificada | Crítica (9) | 1.9% | — | Marktext | 29/1/2022 | 17/6/2026 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload. | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Crítica (9.8) | 5.2% | — | Itextpdf ItextDebian Linux | 15/12/2021 | 17/6/2026 | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. | |
| Modificada | Media (4.8) | 0.62% | — | Wooassist Storefront Footer Text | 8/11/2021 | 17/6/2026 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed. | |
| Modificada | Alta (7.8) | 0.66% | — | Text2pdf Project Text2pdf | 3/11/2021 | 17/6/2026 | An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts. | |
| Modificada | Media (5.4) | 0.91% | — | Content Text Slider ON Post Project Content Text Slider ON Post | 1/11/2021 | 17/6/2026 | The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues | |
| Modificada | Media (4.8) | 0.62% | — | Wp-special-textboxes Project Wp-special-textboxes | 25/10/2021 | 17/6/2026 | The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Media (6.1) | 0.90% | — | Webodid Dropdown AND Scrollable Text | 10/9/2021 | 17/6/2026 | The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0. | |
| Modificada | Media (5.4) | 1.1% | — | Textpattern | 19/8/2021 | 17/6/2026 | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting the 'Articles' page. | |
| Modificada | Media (5.4) | 1.0% | — | Textpattern | 19/8/2021 | 17/6/2026 | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head. | |
| Modificada | Alta (7.8) | 1.4% | — | Opentext Brava! Desktop | 3/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | |
| Modificada | Alta (7.8) | 1.4% | — | Opentext Brava! Desktop | 3/8/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | |
| Modificada | Media (4.8) | 0.51% | — | Textpattern | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature. | |
| Modificada | Alta (7.2) | 1.0% | — | Oracle Text | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF… | |
| Modificada | Alta (7.8) | 1.8% | — | Opentext Brava! Desktop | 29/6/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM… |