Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

2488 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.59%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora12/4/202317/6/2026
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
ModificadaMedia (6.5)0.46%—Jenkins Image TAG Parameter12/4/202317/6/2026
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.
ModificadaAlta (7.8)0.60%—Microsoft RAW Image Extension11/4/202317/6/2026
Raw Image Extension Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.62%—Microsoft RAW Image Extension11/4/202317/6/2026
Raw Image Extension Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.38%—I13websolution Continuous Image Carosel With Lightbox7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin <= 1.0.15 versions.
ModificadaMedia (4.8)0.39%—Wpdevart Download Image AND Video Lightbox, Image Popup6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions.
ModificadaMedia (5.4)0.47%—Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder3/4/202317/6/2026
The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.5)0.86%—Openimageio30/3/202317/6/2026
An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.5)1.3%—Openimageio30/3/202317/6/2026
A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.
ModificadaAlta (7.5)0.94%—Openimageio30/3/202317/6/2026
An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaMedia (5.4)0.38%—Webdevocean Image Hover Effects FOR Wpbakery Page Builder30/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
ModificadaMedia (4.8)0.42%—Mrdigital Simple Image Popup29/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions.
ModificadaMedia (6.1)0.42%—Wpdevart Image AND Video Gallery With Thumbnails29/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
ModificadaMedia (4.8)0.37%—Wpmart Interactive SVG Image MAP Builder28/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.
ModificadaMedia (6.1)0.41%—Oxilab Image Hover Effects FOR Elementor With Lightbox AND Flipbox28/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
ModificadaMedia (5.4)0.44%—WP Image Carousel Project WP Image Carousel27/3/202317/6/2026
The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.86%—ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux23/3/202317/6/2026
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When…
ModificadaMedia (5.4)0.38%—Robogallery Gallery Images APE21/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions.
ModificadaCrítica (9.8)2.0%—Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP16/3/202317/6/2026
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
ModificadaAlta (8.8)1.6%—Cm-wp Auto Featured Image13/3/202317/6/2026
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.
ModificadaAlta (7.8)0.38%—Imageinfo Project Imageinfo6/3/202317/6/2026
A vulnerability was found in xiaozhuai imageinfo up to 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file imageinfo.hpp. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.43%—Easyimages2.0 Project Easyimages2.05/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.
ModificadaMedia (4.3)0.23%—Imagely Nextgen Gallery1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
ModificadaMedia (5.5)0.31%—Golang ImageGolang TiffFedoraproject Fedora28/2/202317/6/2026
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
ModificadaMedia (6.1)0.88%💥 ExploitShortpixel Adaptive Images27/2/202317/6/2026
The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin