Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

193 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)78%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG20/4/20231/10/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the…
ModificadaCrítica (9.8)0.74%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System27/3/202317/6/2026
A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can…
ModificadaMedia (6.1)0.39%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Automatic Question Paper Generator System 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_class. The manipulation of the argument description leads to cross site scripting. The attack may be…
ModificadaCrítica (9.8)0.54%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be…
ModificadaCrítica (9.8)0.54%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Automatic Question Paper Generator System 1.0. This affects an unknown part of the file classes/Users.php?f=save_ruser. The manipulation of the argument id/email leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaCrítica (9.8)0.84%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The…
ModificadaCrítica (9.8)0.82%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql…
ModificadaAlta (8.8)0.78%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to…
ModificadaCrítica (9.8)3.0%💥 PoCNewspaperclub PDF Info23/2/202317/6/2026
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
ModificadaCrítica (9.8)3.8%💥 ExploitNewsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer14/11/202217/6/2026
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
ModificadaMedia (6.1)1.1%💥 ExploitTagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.1)0.60%—Tagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.60%—Books & Papers Project Books & Papers25/4/202217/6/2026
The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)1.2%—Automatic Question Paper Generator Project Automatic Question Paper Generator18/4/202217/6/2026
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
ModificadaMedia (6.1)0.56%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System29/3/202217/6/2026
A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This affects the file /aqpg/users/login.php of the component My Account Page. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate…
ModificadaCrítica (9.8)0.81%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System29/3/202217/6/2026
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
ModificadaMedia (5.3)0.75%💥 PoCSamsung Livewallpaperservice11/2/202217/6/2026
An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.
ModificadaAlta (7.5)1.4%—Flowpaper Pdf2json10/11/202117/6/2026
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
ModificadaCrítica (9.8)1.8%—Flowpaper Pdf2json10/11/202117/6/2026
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 .
ModificadaMedia (5.5)0.67%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception.
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) .
Orbitaley — Vulnerabilidades