Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.29% | — | Ultimate Before After Image Slider GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an… | |
| Pendiente de análisis | Alta (7) | 0.14% | — | HP ImagediagsAI | 31/8/2026 | 3/9/2026 | A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Aplazada | Alta (7.5) | 0.50% | — | Yx-image-recognitionAI | 26/8/2026 | 31/8/2026 | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation. | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI | 25/8/2026 | 28/8/2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Image Photo Gallery Final Tiles GridAI | 22/8/2026 | 24/8/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Alta (7.8) | 0.45% | — | Huggingface Pytorch Image ModelsAI | 20/8/2026 | 31/8/2026 | Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpo-hr NGG Smart Image SearchAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Ewww Image OptimizerAI | 19/8/2026 | 20/8/2026 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.37% | — | Confidential Containers Guest ComponentsAIImage-rs Image RSAI | 18/8/2026 | 9/9/2026 | Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside its destination directory. In image-rs/src/stream/unpack.rs,… | |
| Aplazada | Alta (8.8) | 0.66% | — | T-systems International Gmbh ImagemasterAI | 17/8/2026 | 9/9/2026 | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function. | |
| Aplazada | Media (5.7) | 0.15% | — | Manual Image CropAI | 16/8/2026 | 26/8/2026 | The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that crops attachment images; its only guard passes for any logged-in user. A subscriber-level user can therefore supply an arbitrary attachment ID and overwrite that… | |
| Aplazada | Media (4.3) | 0.43% | — | Shortpixel Adaptive ImagesAI | 16/8/2026 | 20/8/2026 | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.41% | — | Image Uploader FOR WelcartAI | 15/8/2026 | 20/8/2026 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Pendiente de análisis | Alta (7.5) | 0.41% | — | Golang X ImageAI | 14/8/2026 | 3/9/2026 | VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion. | |
| Modificada | Media (5.5) | 0.16% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/8/2026 | 2/10/2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This… | |
| Aplazada | Media (6.5) | 0.22% | — | Fifu Featured Image From URLAI | 13/8/2026 | 14/8/2026 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | |
| Analizada | Media (5.5) | 0.15% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 12/8/2026 | 1/9/2026 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the… | |
| Aplazada | Alta (8.7) | 2.5% | — | FilerunAIFfmpegAIImagemagickAIVipsAI+1 | 11/8/2026 | 16/9/2026 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in… | |
| Aplazada | Baja (1.9) | 0.17% | — | Ichigo3766 Image-gen-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. The project was informed of the problem… | |
| Aplazada | Alta (7.5) | 0.51% | — | Perl ImagerAI | 7/8/2026 | 26/8/2026 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and… | |
| Modificada | Media (5.1) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of… | |
| Modificada | Alta (7.3) | 0.18% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers. | |
| Modificada | Media (6.5) | 0.52% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit… | |
| Aplazada | Alta (7.5) | 0.46% | — | ImagecliAI | 5/8/2026 | 28/8/2026 | imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function… | |
| Aplazada | Alta (7.5) | 0.46% | — | ImagecliAI | 5/8/2026 | 28/8/2026 | imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and… |