Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

305 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.45%—Rockcontent Rock Convert3/11/202217/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.
ModificadaMedia (4.8)0.53%—Rockcontent Rock Convert31/10/202217/6/2026
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.54%—Rockcontent Rock Convert31/10/202217/6/2026
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.5)0.37%—Convert2rhel Project Convert2rhelRedhat Enterprise Linux29/8/202217/6/2026
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red…
ModificadaMedia (5.5)0.32%—Convert2rhel Project Convert2rhelRedhat Enterprise Linux29/8/202217/6/2026
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps.…
ModificadaCrítica (9.8)3.1%—Font Converter Project Font Converter29/8/202217/6/2026
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.
ModificadaMedia (5.4)1.4%—Jupyter NbconvertDebian Linux18/8/202217/6/2026
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks…
ModificadaAlta (7.8)0.54%—Anvsoft PDF Converter24/7/202217/6/2026
A vulnerability has been found in Anvsoft PDFMate PDF Converter Pro 1.7.5.0 and classified as critical. The manipulation leads to memory corruption. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)11%—Convert-svg-core Project Convert-svg-core22/7/202217/6/2026
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
ModificadaMedia (5.5)0.21%—Convert2rhel Project Convert2rhel14/7/202217/6/2026
In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view the password via the process list while convert2rhel is running. However, this ansible playbook is…
ModificadaCrítica (9.3)1.3%—Modelconverter Project Modelconverter11/7/202217/6/2026
The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)0.62%—Jenkins Convertigo Mobile Platform23/6/202217/6/2026
A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
ModificadaAlta (8.8)0.53%—Jenkins Convertigo Mobile Platform23/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.
ModificadaMedia (6.5)0.69%—Jenkins Convertigo Mobile Platform23/6/202217/6/2026
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
ModificadaAlta (7.8)0.90%—Convert-svg-core Project Convert-svg-core10/6/202217/6/2026
The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.
ModificadaCrítica (9.8)2.2%—Convert-svg Project Convert-svg10/6/202217/6/2026
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
ModificadaCrítica (9.8)34%—Subconverter Project Subconverter19/5/202217/6/2026
A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters.
ModificadaMedia (5.5)0.69%—Cvrf-csaf-converter Project Cvrf-csaf-converter15/3/202217/6/2026
CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the system running the converter.
ModificadaMedia (6.5)0.81%—Jenkins Convertigo Mobile Platform15/2/202217/6/2026
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
ModificadaMedia (6.1)2.2%💥 ExploitWebp Converter FOR Media Project Webp Converter FOR Media24/1/202217/6/2026
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
ModificadaAlta (7.5)2.0%—Convert-svg-core Project Convert-svg-core21/1/202217/6/2026
This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a converted PNG file.
ModificadaMedia (6.5)1.1%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.
ModificadaAlta (7.5)1.5%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.
ModificadaAlta (7.5)1.2%—Subconverter Project Subconverter20/12/202017/6/2026
tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary %URL% value and launches a GET request for it, but does not consider that the external request target may indirectly redirect back to this original /sub endpoint. Thus, a request loop and a denial…
ModificadaAlta (7.5)4.1%—Convert\ \Fedoraproject Fedora7/4/202017/6/2026
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.