Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | Graphicsmagick | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format. | |
| Modificada | Alta (7.5) | 1.4% | — | Dgtl Huemagic | 11/8/2023 | 17/6/2026 | Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ezsoftmagic MP3 Audio Converter | 10/8/2023 | 17/6/2026 | EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow. | |
| Modificada | Alta (8.8) | 0.73% | — | Esds.co Emagic Data Center Management | 8/8/2023 | 17/6/2026 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system. | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Esds.co Emagic Data Center Management | 8/8/2023 | 17/6/2026 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary… | |
| Modificada | Baja (3.3) | 0.35% | — | ImagemagickFedoraproject Fedora | 8/8/2023 | 17/6/2026 | ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw. | |
| Modificada | Crítica (9.8) | 0.89% | — | Code4craft Webmagic | 28/7/2023 | 17/6/2026 | webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader. | |
| Modificada | Media (5.5) | 0.46% | — | Imagemagick | 24/7/2023 | 17/6/2026 | A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.3% | — | H3C Magic B1st Firmware | 28/6/2023 | 17/6/2026 | A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.91% | 💥 PoC | H3C Magic B1stw Firmware | 26/6/2023 | 17/6/2026 | H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Media (5.5) | 0.50% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.37% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 1.0% | — | Imagemagick | 6/6/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing. | |
| Modificada | Alta (7.2) | 0.93% | — | H3C Magic R300-2100m Firmware | 31/5/2023 | 17/6/2026 | H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm. | |
| Modificada | Alta (7.2) | 0.93% | — | H3C Magic R300-2100m Firmware | 31/5/2023 | 17/6/2026 | H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm. |