Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
23.383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.42% | — | Dompdf Project Dompdf | 28/7/2026 | 4/8/2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document.… | |
| Analizada | Media (6.3) | 0.90% | — | Dompdf Project Dompdf | 28/7/2026 | 4/8/2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document containing a single image with massive dimensions (e.g., 30,000x30,000 pixels). While… | |
| Analizada | Media (6.3) | 0.64% | 💥 PoC | Dompdf Project Dompdf | 28/7/2026 | 4/8/2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD. A 58-byte BMP whose header declares e.g. 6000×6000 is accepted and later… | |
| Analizada | Media (6.3) | 0.45% | — | Dompdf Project Dompdf | 28/7/2026 | 4/8/2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a data: URI, because dompdf processes the SVG twice and the second pass does not enforce the same… | |
| Analizada | Baja (2.3) | 0.51% | — | Dompdf Project Dompdf | 28/7/2026 | 5/8/2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion.… | |
| Analizada | Baja (2.3) | 0.45% | — | Dompdf Project Dompdf | 28/7/2026 | 5/8/2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with realpath() . Because normalization strips the trailing directory separator from $chrootPath , the check only verifies that… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser… | |
| Analizada | Media (4.6) | 0.24% | — | Zephyrproject Zephyr | 27/7/2026 | 1/9/2026 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state != CMD_SEND, and dw->state is only reset to READY on a STOP interrupt. The START_DET interrupt, whose handler in… | |
| Analizada | Alta (7.8) | 0.17% | — | Zephyrproject Zephyr | 27/7/2026 | 12/8/2026 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value for src_id (e.g. -1) trivially satisfied this check and was forwarded into… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store… | |
| Aplazada | Alta (7.1) | 0.61% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting… | |
| Analizada | Alta (7) | 0.11% | — | Zephyrproject Zephyr | 25/7/2026 | 12/8/2026 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) syscall concurrently can both… | |
| Analizada | Media (4.6) | 0.24% | — | Zephyrproject Zephyr | 24/7/2026 | 1/9/2026 | The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision and feature flags, but did not verify that the on-disk fields s_blocks_per_group and s_inodes_per_group are… | |
| Aplazada | Crítica (9.1) | 0.41% | — | Project Management BUG AND Issue Tracking PluginAI | 24/7/2026 | 24/7/2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | 389 Project 389 DS BaseAI | 22/7/2026 | 22/7/2026 | A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation. | |
| Analizada | Media (4.3) | 0.26% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft In-memory Project Discovery | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 12/8/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.34% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Baja (3.1) | 0.25% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Project Intelligence | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… |