Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.2%—Dompdf Project Dompdf18/7/202217/6/2026
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
ModificadaMedia (5.3)1.00%—Dompdf Project Dompdf28/6/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaCrítica (9.8)82%💥 ExploitDompdf Project Dompdf3/4/202217/6/2026
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
ModificadaAlta (8.8)1.6%—Html2pdf Project Html2pdf18/1/202217/6/2026
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.
ModificadaCrítica (9.8)5.4%💥 PoCMarkdown TO PDF Project Markdown TO PDF10/12/202117/6/2026
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
ModificadaAlta (7.8)0.66%—Text2pdf Project Text2pdf3/11/202117/6/2026
An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.
ModificadaMedia (5.5)1.3%—Qpdf Project Qpdf20/7/202117/6/2026
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
ModificadaAlta (7.5)1.7%—Pikepdf Project PikepdfFedoraproject Fedora1/4/202117/6/2026
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
ModificadaAlta (8.8)4.5%—Dompdf Project Dompdf10/1/202017/6/2026
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
ModificadaMedia (6.5)1.2%—Dompdf Project Dompdf10/1/202017/6/2026
DOMPDF before 0.6.2 allows denial of service.
ModificadaMedia (6.5)1.5%—Dompdf Project Dompdf10/1/202017/6/2026
DOMPDF before 0.6.2 allows Information Disclosure.
ModificadaAlta (7.5)1.9%—Html-pdf Project Html-pdf20/9/201917/6/2026
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
ModificadaCrítica (9.1)4.4%—Article2pdf Project Article2pdf27/3/201917/6/2026
An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The…
ModificadaAlta (7.5)3.7%—Article2pdf Project Article2pdf27/3/201917/6/2026
A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in.
ModificadaAlta (8.8)2.1%—Mpdf Project Mpdf4/2/201917/6/2026
mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger…
ModificadaCrítica (10)2.1%—Mpdf Project Mpdf7/11/201817/6/2026
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising…
ModificadaBaja (3.3)1.2%—Qpdf Project Qpdf6/10/201817/6/2026
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
ModificadaMedia (5.5)0.50%—Markdown-pdf Project Markdown-pdf20/7/201817/6/2026
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
ModificadaAlta (7.8)1.7%—Qpdf Project QpdfCanonical Ubuntu Linux10/4/201817/6/2026
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
ModificadaMedia (5.5)1.1%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.
ModificadaMedia (5.5)1.1%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.
ModificadaMedia (5.5)0.67%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.
ModificadaMedia (5.5)1.1%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.