Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.6% | — | Jpeg-compressor Project Jpeg Compressor | 1/7/2018 | 17/6/2026 | An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 1.6% | — | Jpeg-compressor Project Jpeg Compressor | 30/6/2018 | 17/6/2026 | An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact. | |
| Modificada | Media (5.5) | 3.7% | 💥 PoC | Apache Commons CompressOracle Mysql ClusterOracle Weblogic Server | 16/3/2018 | 17/6/2026 | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.5) | 2.5% | — | Wpmudev Smush Image Compression AND Optimization | 6/10/2017 | 17/6/2026 | The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal. | |
| Modificada | Alta (7.8) | 3.3% | — | Foxitsoftware PDF Compressor | 16/8/2017 | 17/6/2026 | Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. | |
| Modificada | Media (5) | 13% | — | Apache Commons Compress | 29/6/2012 | 16/6/2026 | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs. | |
| Modificada | Media (4.3) | 2.6% | — | Compress-raw-bzip2 | 19/8/2009 | 16/6/2026 | Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. | |
| Modificada | Media (6.8) | 7.4% | 💥 Exploit | Paul Marquess Compress-raw-zlib Perl Module | 16/6/2009 | 16/6/2026 | Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer… | |
| Modificada | Alta (9.3) | 4.8% | — | Dart Ziplite Compression | 24/5/2007 | 16/6/2026 | Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856. | |
| Modificada | Alta (9.3) | 7.2% | 💥 Exploit | Dart Powertcp ZIP Compression | 24/5/2007 | 16/6/2026 | Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855. | |
| Modificada | Media (5.1) | 4.0% | — | Becubed Compression Plus | 6/9/2006 | 16/6/2026 | Stack-based buffer overflow in the ReadFile function in the ZOO-processing exports in the BeCubed Compression Plus before 5.0.1.28, as used in products including (1) Tumbleweed EMF, (2) VCOM/Ontrack PowerDesk Pro, (3) Canyon Drag and Zip, (4) Canyon Power File, and (5) Canyon Power File Gold, allow context-dependent… | |
| Modificada | Alta (7.5) | 5.8% | — | Ncompress | 14/8/2006 | 16/6/2026 | The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow. | |
| Modificada | Media (6.4) | 6.0% | 💥 Exploit | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter. | |
| Modificada | Baja (2.1) | 0.37% | — | Ncompress | 20/9/2005 | 16/6/2026 | ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970. | |
| Modificada | Alta (7.5) | 4.8% | — | Ncompress | 23/12/2004 | 16/6/2026 | Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument. |