Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.16% | — | Pypdf Project Pypdf | 22/6/2026 | 24/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixed in 6.13.0. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form XObject with self-references. This vulnerability is fixed in 6.12.2. | |
| Analizada | Media (5.1) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2. | |
| Analizada | Media (6.9) | 0.18% | — | Pypdf Project Pypdf | 28/5/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements. This vulnerability is fixed in 6.12.1. | |
| Analizada | Media (5.1) | 0.17% | — | Pypdf Project Pypdf | 28/5/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0. | |
| Analizada | Media (4.8) | 0.18% | — | Pypdf Project Pypdf | 28/5/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulnerability is fixed in 6.12.0. | |
| Analizada | Media (4.8) | 0.41% | — | Pypdf Project Pypdf | 22/4/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2. As a workaround,… | |
| Analizada | Media (4.8) | 0.38% | — | Pypdf Project Pypdf | 22/4/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As a workaround, one… | |
| Analizada | Media (4.8) | 0.41% | — | Pypdf Project Pypdf | 22/4/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor parameters. This… | |
| Analizada | Media (6.9) | 0.52% | — | Pypdf Project Pypdf | 22/4/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This has been fixed in… | |
| Analizada | Media (6.9) | 0.52% | — | Pypdf Project Pypdf | 17/4/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata. This issue has been fixed in version… | |
| Modificada | Alta (8.4) | 0.20% | — | Gonitro Nitro PDF PRO | 13/4/2026 | 5/7/2026 | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. Because… | |
| Modificada | Alta (7.5) | 0.43% | — | Gonitro Nitro PDF PRO | 13/4/2026 | 5/7/2026 | Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the… | |
| Analizada | Alta (7.5) | 0.44% | — | Gonitro Nitro PDF PRO | 13/4/2026 | 17/6/2026 | A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet. | |
| Analizada | Media (4.6) | 0.58% | — | Pypdf Project Pypdf | 27/3/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has been fixed in pypdf 6.9.2. If users cannot upgrade yet, consider applying the changes… | |
| Analizada | Media (5.1) | 0.37% | — | Pypdf Project Pypdf | 20/3/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with many entries. This issue has been fixed in version 6.9.1. | |
| Analizada | Media (6.8) | 0.18% | — | Pypdf Project Pypdf | 10/3/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing a content stream with a rather large /Length value, regardless of the actual data length inside the stream. This vulnerability is… | |
| Analizada | Media (6.9) | 0.53% | — | Pypdf Project Pypdf | 6/3/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5. | |
| Analizada | Media (6.9) | 0.53% | — | Pypdf Project Pypdf | 27/2/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround, consider applying… | |
| Analizada | Media (6.6) | 0.64% | — | Pypdf Project Pypdf | 26/2/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been… | |
| Modificada | Baja (1.2) | 0.61% | — | Pypdf Project Pypdf | 25/2/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually. | |
| Analizada | Media (6.9) | 0.18% | — | Pypdf Project Pypdf | 20/2/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte decompression is used. This vulnerability is fixed in 6.7.1. | |
| Analizada | Media (6.9) | 0.18% | — | Pypdf Project Pypdf | 20/2/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry of a font with unusually large values, for example during text extraction. This… |