Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2448 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.29%—Ultimate Before After Image Slider GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an…
Pendiente de análisisAlta (7)0.14%—HP ImagediagsAI31/8/20263/9/2026
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (7.5)0.50%—Yx-image-recognitionAI26/8/202631/8/2026
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
Pendiente de análisisCrítica (9.1)0.23%—Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI25/8/202628/8/2026
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
AplazadaMedia (6.4)0.33%—Image Photo Gallery Final Tiles GridAI22/8/202624/8/2026
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
Pendiente de análisisAlta (7.8)0.45%—Huggingface Pytorch Image ModelsAI20/8/202631/8/2026
Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the…
AplazadaCrítica (9.3)0.40%—Wpo-hr NGG Smart Image SearchAI19/8/202620/8/2026
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
AplazadaMedia (6.4)0.42%—Ewww Image OptimizerAI19/8/202620/8/2026
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.37%—Confidential Containers Guest ComponentsAIImage-rs Image RSAI18/8/20269/9/2026
Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside its destination directory. In image-rs/src/stream/unpack.rs,…
AplazadaAlta (8.8)0.66%—T-systems International Gmbh ImagemasterAI17/8/20269/9/2026
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
AplazadaMedia (5.7)0.15%—Manual Image CropAI16/8/202626/8/2026
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that…
AplazadaMedia (4.3)0.43%—Shortpixel Adaptive ImagesAI16/8/202620/8/2026
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (6.5)0.41%—Image Uploader FOR WelcartAI15/8/202620/8/2026
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
Pendiente de análisisAlta (7.5)0.41%—Golang X ImageAI14/8/20263/9/2026
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
ModificadaMedia (5.5)0.16%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux14/8/20262/10/2026
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This…
AplazadaMedia (6.5)0.22%—Fifu Featured Image From URLAI13/8/202614/8/2026
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
AnalizadaMedia (5.5)0.15%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux12/8/20261/9/2026
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the…
AplazadaAlta (8.7)2.5%—FilerunAIFfmpegAIImagemagickAIVipsAI+111/8/202616/9/2026
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in…
AplazadaBaja (1.9)0.17%—Ichigo3766 Image-gen-mcpAI9/8/202612/8/2026
A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. The project was informed of the problem…
AplazadaAlta (7.5)0.51%—Perl ImagerAI7/8/202626/8/2026
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and…
ModificadaMedia (5.1)0.17%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of…
ModificadaAlta (7.3)0.18%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
ModificadaMedia (6.5)0.52%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit…
AplazadaAlta (7.5)0.46%—ImagecliAI5/8/202628/8/2026
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function…
AplazadaAlta (7.5)0.46%—ImagecliAI5/8/202628/8/2026
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and…
Orbitaley — Vulnerabilidades