Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 42% | 💥 Exploit | Artifex GhostscriptFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+7 | 21/3/2019 | 17/6/2026 | In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. | |
| Modificada | Alta (7.2) | 2.8% | — | Articatech Artica Proxy | 1/2/2019 | 17/6/2026 | Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin and ldap_password fields, using these credentials at logon.php, and then entering the commands in the admin.index.php command-line field. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex Mupdf | 11/1/2019 | 17/6/2026 | svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 11/1/2019 | 17/6/2026 | Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c. | |
| Modificada | Alta (7.8) | 0.33% | — | Jfrog Artifactory | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian Linux | 2/1/2019 | 17/6/2026 | In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file. | |
| Modificada | Alta (7.8) | 2.9% | — | Artifex GhostscriptDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 20/12/2018 | 17/6/2026 | In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to… | |
| Modificada | Alta (8.1) | 2.0% | — | Artica Integria IMS | 20/12/2018 | 17/6/2026 | Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user accounts can be taken over. This attack… | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Artica Integria IMS | 18/12/2018 | 17/6/2026 | Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known. | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Artica Integria IMS | 17/12/2018 | 17/6/2026 | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex Mupdf | 6/12/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 6/12/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl. | |
| Modificada | Alta (7.8) | 1.2% | — | Artifex GhostscriptRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 3/12/2018 | 17/6/2026 | It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat… | |
| Modificada | Media (5.5) | 1.1% | — | Artifex MupdfDebian Linux | 30/11/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion. | |
| Modificada | Alta (7.8) | 9.5% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same. | |
| Modificada | Media (6.1) | 0.64% | — | Articlecms Project Articlecms | 23/11/2018 | 17/6/2026 | ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. | |
| Modificada | Crítica (9.8) | 7.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+4 | 21/11/2018 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 26/10/2018 | 17/6/2026 | There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool. | |
| Modificada | Alta (8.6) | 16% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxArtifex GPL Ghostscript+7 | 19/10/2018 | 17/6/2026 | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. | |
| Modificada | Media (6.3) | 2.7% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 15/10/2018 | 17/6/2026 | Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object. | |
| Modificada | Alta (8.6) | 10.0% | 💥 Exploit | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 15/10/2018 | 17/6/2026 | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Thephpfactory Article Factory Manager | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Cwjoomla CW Article Attachments FreeCwjoomla CW Article Attachments PRO | 20/9/2018 | 17/6/2026 | The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php. |