Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution. | |
| Modificada | Media (5.4) | 1.4% | — | Plotly | 15/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post. | |
| Modificada | Media (6.1) | 0.91% | — | Plotly | 27/8/2019 | 17/6/2026 | The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors. | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo… | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript… | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is… | |
| Modificada | Media (6.1) | 0.88% | — | Plotly.js | 17/7/2017 | 17/6/2026 | Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue. | |
| Modificada | Alta (7.8) | 0.87% | — | Gnuplot | 15/6/2017 | 17/6/2026 | An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file. | |
| Modificada | Alta (9.3) | 1.1% | — | Plotsoft Pdfill PDF Editor | 27/9/2011 | 16/6/2026 | Untrusted search path vulnerability in PlotSoft PDFill PDF Editor 8.0 allows local users to gain privileges via a Trojan horse mfc70enu.dll or mfc80loc.dll in the current working directory. | |
| Modificada | Alta (9.3) | 4.0% | — | Exeter Winplot | 23/9/2009 | 16/6/2026 | Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file. | |
| Modificada | Alta (7.2) | 0.47% | — | Gnuplot | 31/12/2002 | 16/6/2026 | Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors. |