Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.6%—Gnuplot16/9/202017/6/2026
gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.
ModificadaMedia (5.4)1.4%—Plotly15/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.
ModificadaMedia (6.1)0.91%—Plotly27/8/201917/6/2026
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo…
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript…
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is…
ModificadaMedia (6.1)0.88%—Plotly.js17/7/201717/6/2026
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.
ModificadaAlta (7.8)0.87%—Gnuplot15/6/201717/6/2026
An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.
ModificadaAlta (9.3)1.1%—Plotsoft Pdfill PDF Editor27/9/201116/6/2026
Untrusted search path vulnerability in PlotSoft PDFill PDF Editor 8.0 allows local users to gain privileges via a Trojan horse mfc70enu.dll or mfc80loc.dll in the current working directory.
ModificadaAlta (9.3)4.0%—Exeter Winplot23/9/200916/6/2026
Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file.
ModificadaAlta (7.2)0.47%—Gnuplot31/12/200216/6/2026
Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.