Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2449 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.17% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible… | |
| Aplazada | Media (5.3) | 0.30% | — | GD SecurityimageAI | 17/7/2026 | 17/7/2026 | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The built-in rand function is unsuitable for… | |
| Aplazada | Crítica (9.8) | 0.70% | — | EpegAIPerl Image EpegAI | 16/7/2026 | 17/7/2026 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project. | |
| Aplazada | Baja (2) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes allocated memory not to be released, which can lead to increased memory consumption. | |
| Aplazada | Media (6.3) | 0.35% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service. | |
| Aplazada | Media (6.3) | 0.22% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service). | |
| Aplazada | Baja (2.1) | 0.14% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 15/7/2026 | 16/7/2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 15/7/2026 | 16/7/2026 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. | |
| Aplazada | Baja (2.1) | 0.10% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is… | |
| Aplazada | Media (6.3) | 0.35% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service. | |
| Analizada | Media (4.8) | 0.17% | — | Imagemagick | 15/7/2026 | 16/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy. | |
| Aplazada | Baja (1) | 0.09% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. | |
| Aplazada | Media (4.8) | 0.15% | — | ImagemagickAI | 15/7/2026 | 15/7/2026 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service. | |
| Aplazada | Media (5.4) | 0.23% | — | Ultimate Before After Image Slider AND GalleryAI | 14/7/2026 | 29/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level… | |
| Aplazada | Media (4.9) | 0.19% | — | Themeisle Auto Featured ImageAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4. | |
| Aplazada | Media (6.4) | 0.23% | — | Bdthemes Instant Image GeneratorAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service. | |
| Analizada | Media (6.3) | 0.55% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution. | |
| Analizada | Media (4.8) | 0.25% | — | Imagemagick | 11/7/2026 | 14/7/2026 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process. | |
| Analizada | Media (6.3) | 0.27% | — | Imagemagick | 11/7/2026 | 13/7/2026 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially crafted XMP data to trigger the vulnerability and cause application crashes. | |
| Analizada | Media (4.8) | 0.17% | — | Imagemagick | 11/7/2026 | 14/7/2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service. |