Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.2) | 0.12% | — | Image Scanner DriverAI | 30/9/2026 | 30/9/2026 | Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance. | |
| Aplazada | Media (5.5) | 0.35% | — | Nothings STB Image WriteAI | 29/9/2026 | 1/10/2026 | A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been… | |
| Pendiente de análisis | Media (6.3) | 0.32% | — | ImagemagickAI | 29/9/2026 | 30/9/2026 | ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing… | |
| Aplazada | Baja (2.1) | 0.23% | — | Faststone Image ViewerAI | 28/9/2026 | 29/9/2026 | A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Baja (2.1) | 0.23% | — | Faststone Image ViewerAI | 28/9/2026 | 1/10/2026 | A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Baja (2.1) | 0.23% | — | Faststone Image ViewerAI | 28/9/2026 | 29/9/2026 | A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-bounds write. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Baja (2.1) | 0.23% | — | Faststone Image ViewerAI | 28/9/2026 | 29/9/2026 | A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Alta (8.1) | 0.27% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via… | |
| Aplazada | Media (5.3) | 0.23% | — | Image BuzzAI | 22/9/2026 | 22/9/2026 | The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the… | |
| Analizada | Alta (7.6) | 0.29% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer. tiffinput::read_native_scanline_locked()… | |
| Analizada | Media (5.3) | 0.42% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInput::read_native_scanlines() return through an error path while asynchronous… | |
| Analizada | Media (5.5) | 0.20% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is processed during output close. gifsplitpalette() computes numpixels multiplied by the… | |
| Analizada | Alta (8.3) | 0.46% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bit depth 26. cineoninput::open() maps it to a 32-bit imagespec, but libcineon maps… | |
| Analizada | Media (5.5) | 0.19% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses… | |
| Analizada | Alta (7.8) | 0.21% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow when a caller reads a partial edge-tile… | |
| Analizada | Media (5.5) | 0.20% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer stored channel_buffers than the spec.nchannels value advertised by the rawcolor path.… | |
| Analizada | Alta (7.8) | 0.22% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public imagespec while the decoder retains a 32-bit internal pixel size.… | |
| Analizada | Media (6.1) | 0.20% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffinput::readimg() allocate a temporary scanline from m_header.rgba_count but copy… | |
| Analizada | Media (6.1) | 0.20% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked… | |
| Analizada | Media (6.5) | 0.36% | — | Openimageio | 18/9/2026 | 29/9/2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte header blocks without the mandatory end keyword makes fitsinput::read_fits_header()… | |
| Pendiente de análisis | Media (6.3) | 0.31% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory… | |
| Pendiente de análisis | Media (6.3) | 0.29% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56. | |
| Pendiente de análisis | Baja (2.3) | 0.26% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application… | |
| Pendiente de análisis | Media (4.8) | 0.11% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass… |