Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 11% | — | Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 6/9/2019 | 17/6/2026 | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute… | |
| Modificada | Alta (7.8) | 2.0% | — | Artifex GhostscriptRedhat Openshift Container PlatformOpensuse LeapFedoraproject Fedora+1 | 3/9/2019 | 17/6/2026 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or… | |
| Modificada | Alta (7.8) | 3.7% | 💥 PoC | Artifex GhostscriptRedhat Openshift Container PlatformFedoraproject FedoraOpensuse Leap+1 | 3/9/2019 | 17/6/2026 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or… | |
| Modificada | Alta (8.8) | 1.7% | — | Elearningfreak Insert OR Embed Articulate Content | 27/8/2019 | 17/6/2026 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload. | |
| Modificada | Media (6.5) | 0.63% | — | Elearningfreak Insert OR Embed Articulate Content | 27/8/2019 | 17/6/2026 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | |
| Modificada | Crítica (9.8) | 1.6% | — | Artica Integria IMS | 16/8/2019 | 17/6/2026 | filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload. | |
| Modificada | Alta (7.1) | 1.1% | — | Artifex Mupdf | 14/8/2019 | 17/6/2026 | Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex Mupdf | 4/7/2019 | 17/6/2026 | Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node. | |
| Modificada | Crítica (9.8) | 3.2% | — | Artifex Mupdf | 13/6/2019 | 17/6/2026 | Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.7% | — | Artifex Mujs | 13/6/2019 | 17/6/2026 | An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size. | |
| Modificada | Media (6.5) | 0.71% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven… | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… | |
| Modificada | Media (4.3) | 0.84% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials… | |
| Modificada | Media (5.5) | 1.3% | — | Artifex Ghostscript | 23/5/2019 | 17/6/2026 | Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of… | |
| Modificada | Alta (7.8) | 1.8% | — | Artifex GhostscriptDebian LinuxOpensuse LeapFedoraproject Fedora+2 | 16/5/2019 | 17/6/2026 | It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27… | |
| Modificada | Alta (7.5) | 2.3% | — | Artifex Mujs | 22/4/2019 | 17/6/2026 | An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check. | |
| Modificada | Alta (7.5) | 2.1% | — | Artifex MujsFedoraproject Fedora | 22/4/2019 | 17/6/2026 | An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call. | |
| Modificada | Crítica (9.8) | 3.3% | — | Artifex Mujs | 22/4/2019 | 17/6/2026 | An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow. | |
| Modificada | Crítica (9.8) | 3.0% | — | Jfrog Artifactory | 16/4/2019 | 17/6/2026 | JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Jfrog Artifactory | 11/4/2019 | 17/6/2026 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP… | |
| Modificada | Crítica (9.1) | 4.4% | — | Article2pdf Project Article2pdf | 27/3/2019 | 17/6/2026 | An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The… | |
| Modificada | Alta (7.5) | 3.7% | — | Article2pdf Project Article2pdf | 27/3/2019 | 17/6/2026 | A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 25/3/2019 | 17/6/2026 | It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. | |
| Modificada | Media (5.5) | 2.5% | — | Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+7 | 25/3/2019 | 17/6/2026 | It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. |