Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.54% | — | Qpdf Project Qpdf | 11/8/2023 | 17/6/2026 | An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf. | |
| Modificada | Media (4.3) | 0.38% | — | Wp-mpdf Project Wp-mpdf | 12/7/2023 | 17/6/2026 | The wp-mpdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1. This is due to missing or incorrect nonce validation on the mpdf_admin_savepost() function. This makes it possible for unauthenticated attackers to save post data via a forged request granted they can… | |
| Modificada | Media (6.5) | 0.63% | — | Pypdf Project Pypdf | 30/6/2023 | 17/6/2026 | pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It… | |
| Modificada | Media (6.5) | 0.57% | — | Pypdf Project Pypdf | 30/6/2023 | 17/6/2026 | pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%.… | |
| Modificada | Media (5.5) | 0.35% | — | Pypdf Project PypdfPypdf2 Project Pypdf2 | 27/6/2023 | 17/6/2026 | pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (8.2) | 0.60% | — | Markdown-pdf Project Markdown-pdf | 4/4/2023 | 17/6/2026 | markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user. | |
| Modificada | Media (5.4) | 0.49% | — | Embed PDF Project Embed PDF | 27/2/2023 | 17/6/2026 | The Embed PDF WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 2.5% | — | Dompdf Project Dompdf | 7/2/2023 | 17/6/2026 | Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if `href` is specified. However, php-svg-lib,… | |
| Modificada | Crítica (9.8) | 3.6% | 💥 PoC | Dompdf Project Dompdf | 1/2/2023 | 17/6/2026 | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with… | |
| Modificada | Alta (7.5) | 6.0% | 💥 PoC | Dompdf Project Dompdf | 25/9/2022 | 17/6/2026 | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc. | |
| Modificada | Media (5.5) | 0.30% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc. | |
| Modificada | Media (5.5) | 0.30% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a segmentation violation via Lexer::getObj(Object*) at /xpdf/Lexer.cc. | |
| Modificada | Media (5.5) | 0.30% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc. | |
| Modificada | Media (5.5) | 0.46% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a floating point exception (FPE) via DCTStream::decodeImage() at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdf Project Xpdf | 16/8/2022 | 17/6/2026 | XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp. | |
| Modificada | Crítica (9.8) | 0.91% | — | Node-latex-pdf Project Node-latex-pdf | 2/8/2022 | 17/6/2026 | This affects all versions of package node-latex-pdf. | |
| Modificada | Crítica (9.8) | 1.8% | — | Nodepdf Project Nodepdf | 28/7/2022 | 17/6/2026 | Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0. | |
| Modificada | Media (6.5) | 0.76% | — | Qpdf Project Qpdf | 22/7/2022 | 17/6/2026 | QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. |