Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.18% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8. | |
| Modificada | Media (5.5) | 0.20% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value. | |
| Modificada | Media (5.5) | 0.20% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. | |
| Aplazada | Media (4.3) | 0.20% | — | Artifex GhostxpsAI | 22/9/2025 | 30/9/2026 | In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked. | |
| Aplazada | Media (5.9) | 0.22% | — | Artiosmedia RSS Feed PROAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artiosmedia RSS Feed Pro rss-feed-pro allows Stored XSS.This issue affects RSS Feed Pro: from n/a through <= 1.1.8. | |
| Aplazada | Media (4.3) | 0.14% | — | Ays-pro ChartifyAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.5.3. | |
| Aplazada | Media (6.5) | 0.33% | — | Ashish AI Tools Artificial Intelligence Auto Content GeneratorAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Tools: from n/a through <= 4.0.7. | |
| Modificada | Media (6.5) | 0.41% | 💥 PoC | Artifex Mupdf | 4/8/2025 | 5/7/2026 | An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion | |
| Aplazada | Media (6.4) | 0.19% | — | Partnersky System MartinusAI | 19/7/2025 | 17/6/2026 | The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'martinus' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles CalendarAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles Good SearchAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Media (5.3) | 0.43% | — | Artifex GhostpdlAI | 12/7/2025 | 17/6/2026 | A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c of the component New Output File Open Error Handler. The manipulation leads to null pointer dereference. It is… | |
| Aplazada | Media (5.4) | 0.18% | — | Wikimedia Mediawiki Related Articles ExtensionAI | 7/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Smartiolabs Smart NotificationAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartiolabs Smart Notification allows Reflected XSS. This issue affects Smart Notification: from n/a through 10.3. | |
| Analizada | Alta (7) | 36% | 💥 Exploit | Artica Pandora FMS | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 | |
| Aplazada | Baja (0.9) | 0.12% | — | Bharti Airtel Thanks APPAI | 27/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The… | |
| Aplazada | Media (5.9) | 0.26% | — | Felix Martinez Recipes Manager - WPHAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Recipes manager - WPH allows Stored XSS. This issue affects Recipes manager - WPH: from n/a through 1.0.4. | |
| Aplazada | Alta (8.5) | 0.30% | — | Wpexperts WC Partial ShipmentAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Woocommerce Partial Shipment wc-partial-shipment allows SQL Injection.This issue affects Woocommerce Partial Shipment: from n/a through <= 3.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smartiolabs Smart NotificationAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3. | |
| Analizada | Baja (3.3) | 0.32% | 💥 PoC | Artifex Ghostscript | 23/5/2025 | 17/6/2026 | gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. | |
| Aplazada | Media (5.4) | 0.14% | — | Artisanworkshop Japanized FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Cross Site Request Forgery.This issue affects Japanized For WooCommerce: from n/a through <= 2.6.40. | |
| Aplazada | Media (4.3) | 0.14% | — | Artiosmedia Product Code FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in artiosmedia Product Code for WooCommerce product-code-for-woocommerce allows Cross Site Request Forgery.This issue affects Product Code for WooCommerce: from n/a through <= 1.5.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Bundgaard Martins Free Monetized AD Exchange NetworkAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-visitors allows Reflected XSS.This issue affects Martins Free Monetized Ad Exchange Network: from n/a through <= 1.0.6. | |
| Analizada | Media (4.5) | 0.18% | — | Artifex Ghostscript | 26/4/2025 | 17/6/2026 | In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954. | |
| Analizada | Media (6.9) | 0.51% | — | Markparticle Webserver | 21/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit… |