Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
2620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.89% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Existe un error de desbordamiento de montículo en FreeImage antes de 1.18.0 a través de la función ofLoad en PluginJPEG.cpp. | |
| Modificada | Media (6.5) | 0.73% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Vulnerabilidad de desreferencia de puntero NULL en FreeImage antes de 1.18.0 a través de la función FreeImage_CloneTag en FreeImageTag.cpp. | |
| Modificada | Alta (8.8) | 1.2% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Una vulnerabilidad de desbordamiento de montículo en FreeImage 1.18.0 a través de la función ofLoad en PluginTIFF.cpp. | |
| Modificada | Media (6.5) | 0.73% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Se ha descubierto un problema de agotamiento de pila en FreeImage anterior a 1.18.0 a través de la función Validate en PluginRAW.cpp. | |
| Modificada | Alta (8.8) | 1.4% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | La vulnerabilidad de desbordamiento de búfer en PSDParser.cpp::ReadImageLine() en FreeImage 3.19.0 [r1859] permite a atacantes remotos ru narbitrary código mediante el uso de archivo psd crafted. | |
| Modificada | Media (6.5) | 0.85% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | La vulnerabilidad de desbordamiento del búfer en la función psdParser::UnpackRLE en PSDParser.cpp en FreeImage 3.19.0 [r1859] permite a atacantes remotos provocar una denegación de servicio a través de la apertura de un archivo psd manipulado. | |
| Modificada | Alta (8.8) | 1.5% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Una vulnerabilidad de desbordamiento del búfer en psdThumbnail::Read en PSDParser.cpp en FreeImage 3.19.0 [r1859] permite a atacantes remotos ejecutar código arbitrario a través de la apertura de un archivo psd manipulado. | |
| Modificada | Alta (8.8) | 1.5% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | La vulnerabilidad de desbordamiento del búfer en la función load de PluginICO.cpp en FreeImage 3.19.0 [r1859] permite a atacantes remotos ejecutar código arbitrario a través de la apertura de un archivo ico manipulado. | |
| Modificada | Alta (7.5) | 1.2% | — | Freedesktop PopplerDebian Linux | 22/8/2023 | 17/6/2026 | La recursión incontrolada en pdfinfo y pdftops en poppler 0.89.0 permite a atacantes remotos provocar una denegación de servicio a través de una entrada manipulada. | |
| Modificada | Media (6.5) | 1.1% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Vulnerabilidad de Desbordamiento de Búfer en la función FreeImage_Load en FreeImage Library 3.19.0 (r1828) permite a los atacantes provocar una denegación de servicio a través de un archivo PFM manipulado. | |
| Modificada | Alta (7.8) | 0.46% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Vulnerabilidad de Desbordamiento de Búfer en la función LoadRGB en PluginDDS.cpp en FreeImage 3.18.0 permite a atacantes remotos ejecutar código arbitrario y causar otros impactos a través de un archivo de imagen manipulado. | |
| Modificada | Alta (7.8) | 0.52% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Vulnerabilidad de Desbordamiento de Búfer en la función LoadPixelDataRLE8 en PluginBMP.cpp en FreeImage 3.18.0 permite a atacantes remotos ejecutar código arbitrario y causar otros impactos a través de un archivo de imagen manipulado. | |
| Modificada | Alta (7.8) | 0.49% | — | Freeimage Project Freeimage | 22/8/2023 | 17/6/2026 | Vulnerabilidad de Desbordamiento de Búfer en la función C_IStream::read en PluginEXR.cpp en FreeImage 3.18.0 permite a atacantes remotos ejecutar código arbitrario y causar otros impactos a través de un archivo de imagen manipulado. | |
| Modificada | Media (6.5) | 0.65% | — | Freedesktop Poppler | 22/8/2023 | 17/6/2026 | Vulnerabilidad de desbordamiento de búfer en HtmlOutputDev::page en poppler 0.75.0 que permite a los atacantes provocar una denegación de servicio. | |
| Modificada | Crítica (9.8) | 0.67% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 21/8/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.67% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 21/8/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0/5.0.12. Affected is an unknown function of the file vm\doctor\edit-doc.php. The manipulation of the argument id00/nic/oldemail/email/spec/Tele leads to sql injection. It is possible to launch… | |
| Modificada | Crítica (9.8) | 0.67% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 21/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been rated as critical. This issue affects some unknown processing of the file \vm\patient\booking-complete.php. The manipulation of the argument userid/apponum/scheduleid leads to sql injection. The attack may… | |
| Modificada | Crítica (9.8) | 0.54% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 21/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduledate leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.67% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 20/8/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (5.5) | 0.53% | — | Freedesktop Poppler | 11/8/2023 | 17/6/2026 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function. | |
| Modificada | Media (6.5) | 1.2% | — | Freedesktop Poppler | 11/8/2023 | 17/6/2026 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function. | |
| Modificada | Baja (3.6) | 0.27% | — | Freedom Dangerzone | 8/8/2023 | 17/6/2026 | Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's terminal. Prior to version 0.4.2, if the container is compromised and can… | |
| Modificada | Media (4.8) | 0.37% | — | Paymentsplugin WP Full Stripe Free | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) almacenado autenticado con permisos de administrador o superior en el plugin Mammothology WP Full Stripe Free en versiones anteriores, e incluyendo la 1.6.1. | |
| Modificada | Alta (7.5) | 0.48% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… | |
| Modificada | Alta (7.5) | 0.47% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… |