Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.76% | — | Siemens Syngo Dynamics Cardiovascular Imaging AND Information System | 17/11/2022 | 17/6/2026 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool. | |
| Modificada | Alta (7.5) | 0.67% | — | Siemens Syngo Dynamics Cardiovascular Imaging AND Information System | 17/11/2022 | 17/6/2026 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool. | |
| Modificada | Crítica (9.8) | 1.9% | — | Medicalexpo ECS Imaging | 11/1/2021 | 17/6/2026 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE:… | |
| Modificada | Crítica (9.8) | 3.1% | — | Evolucare ECS Imaging | 7/1/2021 | 17/6/2026 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the… | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Commons Imaging | 6/5/2019 | 17/6/2026 | Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | |
| Modificada | Alta (7.5) | 1.9% | — | Apache Commons Imaging | 6/5/2019 | 17/6/2026 | Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging. | |
| Modificada | Alta (8.1) | 6.3% | — | HP Linux Imaging AND Printing | 2/8/2017 | 17/6/2026 | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads. | |
| Modificada | Crítica (9.8) | 3.3% | — | Dexis Imaging Suite | 24/9/2016 | 17/6/2026 | DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session. | |
| Modificada | Media (6.5) | 4.0% | — | Python PillowPython Imaging Project Python ImagingDebian Linux | 13/4/2016 | 17/6/2026 | Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file. | |
| Modificada | Media (5) | 3.4% | — | Debian Python-imagingPython PillowOpensuse | 25/8/2014 | 17/6/2026 | PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size. | |
| Modificada | Alta (10) | 11% | — | Python PillowPythonware Python Imaging Library | 27/4/2014 | 17/6/2026 | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py. | |
| Modificada | Baja (2.1) | 0.45% | — | Python PillowPythonware Python Imaging Library | 17/4/2014 | 17/6/2026 | The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes. | |
| Modificada | Media (4.4) | 0.50% | — | Python PillowPythonware Python Imaging Library | 17/4/2014 | 17/6/2026 | The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to… | |
| Modificada | Baja (2.1) | 0.53% | — | HP Linux Imaging AND Printing Project | 15/2/2014 | 16/6/2026 | HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations. | |
| Modificada | Baja (2.1) | 0.49% | — | HP Linux Imaging AND Printing Project | 5/1/2014 | 17/6/2026 | base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file. | |
| Modificada | Media (6.8) | 4.0% | — | HP Linux Imaging AND Printing Project | 9/12/2013 | 17/6/2026 | upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream. | |
| Modificada | Media (6.9) | 0.42% | — | HP Linux Imaging AND Printing Project | 23/9/2013 | 16/6/2026 | The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid… | |
| Modificada | Baja (1.9) | 0.38% | — | HP Linux Imaging AND Printing ProjectRedhat Enterprise Linux | 6/3/2013 | 16/6/2026 | HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than… | |
| Modificada | Baja (1.2) | 0.44% | — | HP Linux Imaging AND Printing Project | 25/5/2012 | 16/6/2026 | The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file. | |
| Modificada | Media (6.8) | 11% | — | HP Linux Imaging AND Printing Project | 29/7/2011 | 16/6/2026 | foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file. | |
| Modificada | Alta (7.5) | 11% | — | HP Linux Imaging AND Printing Project | 20/1/2011 | 16/6/2026 | Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large… | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | EMC Captiva Pixtools Distributed Imaging | 6/10/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Captiva PixTools Distributed Imaging 2.2 allow remote attackers to create or overwrite arbitrary files via the (1) SetLogFileName and (2) WriteToLog methods. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Dspicture Light Imaging ToolkitDspicture PRO Imaging SDK | 6/10/2008 | 16/6/2026 | The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this… | |
| Modificada | Media (4.9) | 0.54% | — | HP Linux Imaging AND Printing Project | 14/8/2008 | 16/6/2026 | The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207. |