Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
2488 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.50% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status. | |
| Modificada | Alta (8.8) | 0.32% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_add_post', 'azh_duplicate_post', 'azh_update_post' and 'azh_remove_post' functions. This makes it possible for… | |
| Modificada | Media (5.4) | 0.48% | — | Page Builder With Image MAP BY Azexo | 3/6/2023 | 17/6/2026 | The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages… | |
| Analizada | Alta (7.8) | 3.1% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. | |
| Modificada | Crítica (9.8) | 8.0% | 💥 PoC | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | |
| Analizada | Media (5.5) | 0.95% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+1 | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | |
| Modificada | Baja (2.7) | 0.66% | — | 10web Image Optimizer | 30/5/2023 | 17/6/2026 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root. | |
| Modificada | Alta (8.8) | 0.26% | — | Import External Images Project Import External Images | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marty Thornley Import External Images plugin <= 1.4 versions. | |
| Modificada | Media (6.1) | 0.43% | — | Easyimages2.0 Project Easyimages2.0 | 23/5/2023 | 17/6/2026 | EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. | |
| Modificada | Alta (8.8) | 0.27% | — | Hover Image Project Hover Image | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m Hover Image plugin <= 1.4.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Nicearma Dnui-delete-not-used-image | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nicearma DNUI plugin <= 2.8.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Studiowombat Shoppable Images | 18/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions. | |
| Modificada | Media (5.3) | 0.54% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C… | |
| Modificada | Media (5.3) | 0.57% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan.… | |
| Modificada | Alta (7.5) | 0.61% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.2% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in mDNS NSEC record registering process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C… | |
| Modificada | Crítica (9.8) | 1.1% | — | Canon Mf642cdw FirmwareCanon Mf644cdw FirmwareCanon Mf741cdw FirmwareCanon Mf743cdw Firmware+41 | 11/5/2023 | 17/6/2026 | Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpmart Interactive SVG Image MAP Builder | 10/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Mauimarketing Update Image TAG ALT Attribute | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Bajorat-media PB SEO Friendly Images | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions. |