Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.16% | — | Hihonor Magic OS | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | |
| Modificada | Alta (7.1) | 0.16% | — | Hihonor Magic OS | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | |
| Modificada | Alta (7.1) | 0.16% | — | Hihonor Magic OS | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | |
| Analizada | Alta (7.1) | 0.16% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | |
| Modificada | Media (5.5) | 0.17% | — | Hihonor Magic UI | 29/12/2023 | 17/6/2026 | Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | |
| Modificada | Alta (7.5) | 0.30% | — | Hihonor Magichome | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Alta (7.5) | 0.28% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Alta (7.5) | 0.30% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Alta (7.5) | 0.34% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | |
| Analizada | Alta (7.1) | 0.11% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | |
| Analizada | Alta (7.1) | 0.11% | — | Honor Magicos | 29/12/2023 | 17/6/2026 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | |
| Modificada | Alta (7.2) | 0.53% | — | Metagauss Registrationmagic | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login:… | |
| Modificada | Crítica (9.1) | 0.56% | — | Magiclogix Msync | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magic Logix MSync.This issue affects MSync: from n/a through 1.0.0. | |
| Modificada | Alta (8.8) | 0.26% | — | Metagauss Registrationmagic | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through… | |
| Modificada | Media (5.4) | 0.43% | — | Wpembedfb Magic Embeds | 20/11/2023 | 17/6/2026 | The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.5) | 0.48% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 19/11/2023 | 17/6/2026 | A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. | |
| Modificada | Baja (3.3) | 0.67% | — | RmagickFedoraproject Fedora | 30/10/2023 | 17/6/2026 | A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion. | |
| Modificada | Crítica (9.8) | 0.82% | — | Dreamsecurity Magicline 4.0 | 30/10/2023 | 17/6/2026 | A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code. | |
| Modificada | Media (5.4) | 0.39% | — | Pogidude Magic Action BOX | 20/10/2023 | 17/6/2026 | The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.17.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Alta (8.8) | 1.1% | — | Orangelab Imagemagick Engine | 20/10/2023 | 17/6/2026 | The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into… | |
| Modificada | Alta (7.5) | 0.20% | — | 3DS Teamwork Cloud NO Magic Release | 9/10/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server. | |
| Modificada | Media (5.5) | 0.31% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 4/10/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. | |
| Modificada | Media (5.4) | 0.34% | — | 3DS Teamwork Cloud NO Magic Release | 13/9/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code. | |
| Modificada | Alta (7.1) | 1.5% | — | ImagemagickFedoraproject Fedora | 22/8/2023 | 17/6/2026 | A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command. | |
| Modificada | Alta (7.5) | 0.95% | — | Imagemagick | 22/8/2023 | 17/6/2026 | An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c. |