Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes it possible for unauthenticated attackers to disable the image… | |
| Modificada | Media (4.3) | 0.25% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes it possible for unauthenticated attackers to enable image… | |
| Modificada | Media (4.3) | 0.35% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.35% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optimizeAllOn function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.37% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (4.3) | 0.37% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (6.1) | 0.38% | — | Imagerecycle PDF & Image Compression | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Imagerecycle PDF & Image Compression | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions. | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Crítica (9.1) | 0.97% | — | Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+88 | 14/3/2022 | 17/6/2026 | The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows… | |
| Modificada | Media (6.9) | 0.36% | — | Dann Frazier Systemimager-server | 18/11/2008 | 16/6/2026 | si_mkbootserver in systemimager-server 3.6.3 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.inetd.conf or (2) /tmp/pxe.conf.*.tmp temporary file. | |
| Modificada | Media (5) | 1.7% | — | Imager | 24/4/2008 | 16/6/2026 | Buffer overflow in Imager 0.42 through 0.63 allows attackers to cause a denial of service (crash) via an image based fill in which the number of input channels is different from the number of output channels. | |
| Modificada | Media (6.4) | 2.1% | — | Canon I-sensysCanon ImagepressCanon ImagerunnerCanon Imagerunner 2620+8 | 29/2/2008 | 16/6/2026 | The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce. | |
| Modificada | Alta (7.8) | 4.9% | — | Tony Cook Imager | 2/5/2007 | 16/6/2026 | Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files. | |
| Modificada | Media (4) | 1.1% | — | Canon Imagerunner 2620Canon Imagerunner 5020Canon Imagerunner 6870Canon Imagerunner 8500+3 | 11/9/2006 | 16/6/2026 | The Remote UI in Canon imageRUNNER includes usernames and passwords when exporting an address book, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Baja (2.6) | 9.2% | 💥 Exploit | Tony Cook Imager | 10/4/2006 | 16/6/2026 | Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference. | |
| Modificada | Alta (7.5) | 1.6% | — | Canon Imagerunner 5000iCanon Imagerunner C3200 | 31/12/2004 | 16/6/2026 | The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25. |