Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

2449 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.46%—ImagecliAI5/8/202628/8/2026
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and…
AplazadaAlta (7.1)0.15%—Tubitak Bilgem Pardus-image-writerAI4/8/202626/8/2026
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
AnalizadaMedia (5.3)0.20%—Imagemagick30/7/20263/8/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.
AnalizadaMedia (4.7)0.12%—Imagemagick30/7/20263/8/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52…
AnalizadaMedia (5)0.13%—Imagemagick30/7/20263/8/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.
AnalizadaMedia (4.7)0.09%—Imagemagick30/7/20263/8/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in…
AplazadaMedia (5.5)0.20%—XEN LibfsimageAI28/7/202628/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
AplazadaMedia (5.5)0.20%—XEN LibfsimageAI28/7/202628/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
AplazadaMedia (5.5)0.20%—XEN LibfsimageAI28/7/202628/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
AplazadaMedia (5.5)0.20%—XEN LibfsimageAI28/7/202628/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
AplazadaMedia (6.1)0.11%—Libfsimage Iso9660 DriverAI28/7/202628/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields without validating them:
AnalizadaMedia (4.8)0.13%—Imagemagick25/7/20264/8/2026
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
AplazadaCrítica (9.8)0.65%—Image WebpAIGoogle LibwebpAI24/7/202631/7/2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP…
AplazadaMedia (5.9)0.24%—Elementor Image CarouselAI23/7/202623/7/2026
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI23/7/202623/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
ModificadaAlta (8.8)0.49%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/202617/8/2026
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
ModificadaAlta (7.5)0.35%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
ModificadaMedia (5.3)0.34%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
AnalizadaAlta (7.5)0.33%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20264/9/2026
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
ModificadaBaja (3.9)0.12%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
AnalizadaAlta (7.5)0.44%—LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+721/7/202622/9/2026
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
ModificadaMedia (5.9)0.10%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
ModificadaMedia (6.5)0.57%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
ModificadaMedia (6.5)0.73%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
AnalizadaMedia (5.3)0.49%—LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+721/7/202622/9/2026
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.