Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.18%—Pypdf Project Pypdf20/2/202617/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as part of outlines. This vulnerability is fixed in 6.7.1.
AnalizadaMedia (5.1)0.45%💥 PoCPypdf Project Pypdf27/1/202617/6/2026
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the outlines/bookmarks. This has been fixed in pypdf 6.6.2. If projects cannot upgrade yet,…
ModificadaAlta (8.7)0.55%—Mpdf Project Mpdf13/1/202617/6/2026
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
AnalizadaBaja (2.7)0.43%—Pypdf Project Pypdf10/1/202617/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files…
AnalizadaBaja (2.7)0.43%—Pypdf Project Pypdf10/1/202617/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for actually invalid files. This can be achieved by omitting…
ModificadaMedia (5.5)0.09%—Gonitro Nitro PDF PRO8/1/202617/6/2026
An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer…
AplazadaMedia (5.3)0.27%—Xforwoocommerce Share Print AND PDF Products FOR WoocommerceAI30/12/20255/10/2026
Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2.
AnalizadaMedia (6.6)0.44%—Pypdf Project Pypdf22/10/202517/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf version 6.1.3.
AnalizadaMedia (6.6)0.44%—Pypdf Project Pypdf22/10/202517/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.
AnalizadaMedia (6.6)0.46%—Pypdf Project Pypdf13/8/202517/6/2026
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content streams are affected on explicit…
ModificadaAlta (7.5)0.76%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
ModificadaAlta (7.5)0.61%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
AnalizadaCrítica (9.8)0.78%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
ModificadaAlta (7.5)0.62%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
ModificadaMedia (6.2)0.81%—Tcpdf Project Tcpdf26/11/202417/6/2026
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.
AnalizadaCrítica (9.8)0.95%—Dompdf Project Dompdf15/11/202417/6/2026
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows…
AnalizadaCrítica (9.8)1.4%—Dompdf Project Dompdf15/11/202417/6/2026
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP…
AplazadaAlta (7.8)0.26%—Nitro PDF PROAIMicrosoft WindowsAI9/10/202417/6/2026
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.
ModificadaAlta (7.5)1.1%💥 PoCTcpdf Project Tcpdf28/5/202417/6/2026
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
ModificadaAlta (7.5)1.3%💥 PoCTcpdf Project TcpdfFedoraproject Fedora19/4/202417/6/2026
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
ModificadaMedia (6.1)0.58%—Tcpdf Project Tcpdf15/4/202417/6/2026
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
ModificadaMedia (5.5)0.44%—Qpdf Project QpdfFedoraproject Fedora29/2/202417/6/2026
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
ModificadaAlta (7.5)1.5%—Dompdf Project Dompdf13/12/202317/6/2026
Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are allowed. One of the validations is that the SVG document does not reference itself. However, prior to version 2.0.4, a recursive chained using two or more SVG documents is…
ModificadaMedia (5.5)0.24%—Pypdf Project Pypdf31/10/202317/6/2026
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That…
ModificadaMedia (6.1)1.5%💥 PoCHtml2pdf Project Html2pdf28/8/202317/6/2026
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
Orbitaley — Vulnerabilidades