Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 1.9% | — | Micromathematics Project Micromathematics | 20/12/2018 | 17/6/2026 | MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to… | |
| Modificada | Media (5.4) | 1.3% | — | Mathjax | 23/7/2018 | 17/6/2026 | MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via The victim must view a page where untrusted content is processed using Mathjax.… | |
| Modificada | Crítica (9.8) | 5.6% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.9% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.6% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.9% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 1.7% | — | Mathjs Project Mathjs | 27/11/2017 | 17/6/2026 | math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object. | |
| Modificada | Crítica (9.8) | 2.4% | — | Mathjs Math.js | 27/11/2017 | 17/6/2026 | math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution. | |
| Modificada | Alta (7.3) | 0.27% | — | Gentoo Sci-mathematics-gimps | 15/9/2017 | 17/6/2026 | The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed. | |
| Modificada | Alta (7.3) | 0.97% | — | Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+8 | 28/2/2017 | 17/6/2026 | Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel… | |
| Modificada | Media (5.4) | 0.27% | — | Tinytap Math FOR Kids - Subtraction | 29/9/2014 | 17/6/2026 | The Math for Kids - Subtraction (aka it.tinytap.attsa.deepsub) application 1.2.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Numbers & Addition! Math Games | 9/9/2014 | 17/6/2026 | The Numbers & Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2En) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (2.1) | 0.94% | — | Mathijs Koenraadt Search API Sorts | 19/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels. | |
| Modificada | Media (4.3) | 2.5% | — | Mathew Winstone Mobile Tools | 27/6/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) Mobile URL field or (2) Desktop URL field to the General configuration page, or the (3) message to the Mobile Tools block message… | |
| Modificada | Alta (7.5) | 1.3% | — | Mathieu Vidal MV Cooking | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012. | |
| Modificada | Media (4.3) | 3.2% | — | Mathopd | 13/2/2012 | 16/6/2026 | Directory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7, when configured with the * construct for mass virtual hosting, allows remote attackers to read arbitrary files via a crafted Host header. | |
| Modificada | Baja (1.9) | 0.32% | — | Wolfram Research Mathematica | 24/5/2010 | 16/6/2026 | Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf. | |
| Modificada | Media (4.3) | 1.5% | — | Wolfram Webmathematica | 27/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script. | |
| Modificada | Media (5) | 1.1% | — | Wolfram Webmathematica | 27/4/2010 | 16/6/2026 | Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 1.1% | — | Mathon Nicolas Tmsw Cleandb | 19/3/2010 | 16/6/2026 | SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Mathias Schreiber NF Cleandb | 19/3/2010 | 16/6/2026 | SQL injection vulnerability in the CleanDB (nf_cleandb) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 5.8% | — | Peter's Math Anti-spam FOR Wordpress | 11/9/2009 | 16/6/2026 | Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip. | |
| Modificada | Alta (7.2) | 0.36% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors. | |
| Modificada | Alta (10) | 2.7% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Forkosh Mathtex | 14/7/2009 | 16/6/2026 | The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag. |