Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | GMO Typesquare Webfonts FOR Conoha | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GMO Internet Group, Inc. TypeSquare Webfonts for ConoHa plugin <= 2.0.3 versions. | |
| Modificada | Crítica (9.8) | 4.8% | — | Fontsy Project Fontsy | 16/1/2023 | 17/6/2026 | The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (5.4) | 0.30% | — | Wp-chgfontsize Project Wp-chgfontsize | 13/6/2022 | 17/6/2026 | The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Media (4.9) | 1.0% | — | FFW Optimize MY Google Fonts | 3/1/2022 | 17/6/2026 | The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin | |
| Modificada | Media (4.8) | 0.62% | — | Flex Local Fonts Project Flex Local Fonts | 13/12/2021 | 17/6/2026 | The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 0.89% | — | WP Google Fonts Project WP Google Fonts | 6/12/2021 | 17/6/2026 | The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 0.62% | — | Fontsplugin Fonts | 20/9/2021 | 17/6/2026 | The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block. | |
| Modificada | Media (4.3) | 2.6% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 23/10/2010 | 16/6/2026 | The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043. | |
| Modificada | Alta (9.3) | 6.8% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 26/8/2010 | 16/6/2026 | Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer… | |
| Modificada | Alta (7.2) | 0.51% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 22/7/2010 | 16/6/2026 | Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than… | |
| Modificada | Alta (9.3) | 6.6% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 22/7/2010 | 16/6/2026 | Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name. | |
| Modificada | Media (5) | 1.5% | — | Arwscripts Fonts Script | 11/2/2010 | 16/6/2026 | Directory traversal vulnerability in viewfile.php in ARWScripts Fonts Script allows remote attackers to read arbitrary local files via directory traversal sequences in a base64-encoded f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |