Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
2487 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Media (6.1) | 0.38% | — | Radiustheme Variation Images Gallery FOR Woocommerce | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions. | |
| Modificada | Media (5.5) | 0.46% | — | Imagemagick | 24/7/2023 | 17/6/2026 | A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.67% | — | Advancedplugins Ultimateimagetool | 20/7/2023 | 17/6/2026 | In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack. | |
| Modificada | Media (4.3) | 0.38% | — | Ewww Image Optimizer | 12/7/2023 | 17/6/2026 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a… | |
| Modificada | Alta (7.8) | 0.75% | — | Microsoft RAW Image Extension | 11/7/2023 | 17/6/2026 | Raw Image Extension Remote Code Execution Vulnerability | |
| Modificada | Media (4.3) | 0.22% | — | Securimage-wp-fixed Project Securimage-wp-fixed | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drew Phillips Securimage-WP plugin <= 3.6.16 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | WP RSS Images Project WP RSS Images | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez WP RSS Images plugin <= 1.1 versions. | |
| Modificada | Media (4.8) | 0.54% | — | Image Protector Project Image Protector | 10/7/2023 | 17/6/2026 | The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.8) | 0.43% | — | Openimageio | 3/7/2023 | 17/6/2026 | Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function. | |
| Modificada | Media (5.4) | 0.35% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check on the ajax_store_save() function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.25% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing nonce validation on the ajax_store_save() function. This makes it possible for unauthenticated attackers to modify… | |
| Modificada | Media (5.4) | 0.53% | — | Lanacodes Lana Text TO Image | 24/6/2023 | 17/6/2026 | The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' and 'lana_text_to_img' shortcode in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Continuous Image Carousel With Lightbox | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin <= 1.0.15 versions. | |
| Modificada | Media (5.5) | 0.50% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.37% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/6/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. | |
| Modificada | Media (6.1) | 0.22% | — | Auto Upload Images Project Auto Upload Images | 13/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 0.89% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Team Circle Image Slider With Lightbox | 9/6/2023 | 17/6/2026 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Wordpress Vertical Image Slider | 9/6/2023 | 17/6/2026 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (4.3) | 0.61% | — | Robogallery Gallery Images APE | 7/6/2023 | 17/6/2026 | The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site functionality or security. | |
| Modificada | Media (5.5) | 1.0% | — | Imagemagick | 6/6/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing. | |
| Modificada | Media (4.3) | 0.21% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_save' function. This makes it possible for unauthenticated attackers to update the post content and inject malicious… | |
| Modificada | Media (4.3) | 0.50% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status. |