Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
193 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 78% | ⚠ Explotación activa💥 Exploit | Papercut MFPapercut NG | 20/4/2023 | 1/10/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 27/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can… | |
| Modificada | Media (6.1) | 0.39% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Automatic Question Paper Generator System 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_class. The manipulation of the argument description leads to cross site scripting. The attack may be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Automatic Question Paper Generator System 1.0. This affects an unknown part of the file classes/Users.php?f=save_ruser. The manipulation of the argument id/email leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.84% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql… | |
| Modificada | Alta (8.8) | 0.78% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Newspaperclub PDF Info | 23/2/2023 | 17/6/2026 | pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Newsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer | 14/11/2022 | 17/6/2026 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Tagdiv Newspaper | 31/10/2022 | 17/6/2026 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.60% | — | Tagdiv Newspaper | 31/10/2022 | 17/6/2026 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.60% | — | Books & Papers Project Books & Papers | 25/4/2022 | 17/6/2026 | The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 1.2% | — | Automatic Question Paper Generator Project Automatic Question Paper Generator | 18/4/2022 | 17/6/2026 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This affects the file /aqpg/users/login.php of the component My Account Page. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate… | |
| Modificada | Crítica (9.8) | 0.81% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely. | |
| Modificada | Media (5.3) | 0.75% | 💥 PoC | Samsung Livewallpaperservice | 11/2/2022 | 17/6/2026 | An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission. | |
| Modificada | Alta (7.5) | 1.4% | — | Flowpaper Pdf2json | 10/11/2021 | 17/6/2026 | pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject. | |
| Modificada | Crítica (9.8) | 1.8% | — | Flowpaper Pdf2json | 10/11/2021 | 17/6/2026 | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 . | |
| Modificada | Media (5.5) | 0.67% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception. | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) . |