Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
1700 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 15/7/2026 | 16/7/2026 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is… | |
| Aplazada | Media (6.3) | 0.35% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service. | |
| Analizada | Media (4.8) | 0.17% | — | Imagemagick | 15/7/2026 | 16/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy. | |
| Aplazada | Baja (1) | 0.09% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. | |
| Aplazada | Media (4.8) | 0.15% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service. | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo Magic MCPAI | 14/7/2026 | 15/7/2026 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the component mcp__getComponentGenerator. The manipulation of the argument rootPath leads to path traversal. An attack has to be… | |
| Aplazada | Baja (2.1) | 0.40% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack requires a local approach. The exploit has… | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service. | |
| Analizada | Media (6.3) | 0.55% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution. | |
| Analizada | Media (4.8) | 0.25% | — | Imagemagick | 11/7/2026 | 14/7/2026 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. | |
| Analizada | Media (6.3) | 0.27% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. | |
| Analizada | Media (4.8) | 0.17% | — | Imagemagick | 11/7/2026 | 14/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. | |
| Analizada | Media (4.8) | 0.33% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method value triggers an out of bounds read, potentially exposing sensitive information or causing denial of service. | |
| Analizada | Media (6.3) | 0.23% | — | Imagemagick | 10/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory. | |
| Analizada | Media (4.8) | 0.17% | — | Imagemagick | 10/7/2026 | 14/7/2026 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion. | |
| Analizada | Media (4.8) | 0.22% | — | Imagemagick | 8/7/2026 | 9/7/2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 8/7/2026 | 10/7/2026 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling… | |
| Aplazada | Media (5.5) | 0.10% | — | ImagemagickAI | 1/7/2026 | 29/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version… | |
| Analizada | Media (5.5) | 0.10% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26. | |
| Analizada | Media (4.7) | 0.09% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |
| Analizada | Media (5.3) | 0.24% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. |