Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

193 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) .
ModificadaMedia (5.5)0.66%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .
ModificadaMedia (5.5)0.63%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .
ModificadaMedia (5.5)0.74%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .
ModificadaMedia (5.5)0.74%—Flowpaper Pdf2json21/7/202117/6/2026
An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.
ModificadaMedia (6.1)0.83%—Tagdiv Newspaper19/7/202117/6/2026
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
ModificadaAlta (7.8)0.54%—Flowpaper Pdf2json5/2/202117/6/2026
Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.
ModificadaMedia (6.1)1.6%—Papermerge2/12/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a…
ModificadaMedia (6.1)9.2%💥 ExploitGraphpaperpress Sell Media14/8/202017/6/2026
A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).
ModificadaCrítica (9.8)1.8%—Papercrop Project Papercrop21/1/202017/6/2026
The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.
ModificadaAlta (7.8)0.32%—Lenovo Paper20/11/201917/6/2026
A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.
ModificadaMedia (6.1)1.1%—Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper22/10/201917/6/2026
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
ModificadaCrítica (9.8)9.3%💥 ExploitTagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
ModificadaCrítica (9.8)2.2%—Tagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
ModificadaCrítica (9.8)53%💥 ExploitFlowpaper Flexpaper3/7/201917/6/2026
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
ModificadaCrítica (9.8)2.5%—Papercut MFPapercut NG6/6/201917/6/2026
An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.
ModificadaAlta (7.8)2.6%💥 ExploitFujitsu Paperstream IP (twain)17/5/201917/6/2026
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported…
ModificadaCrítica (9.8)3.9%—Papercut MFPapercut NG20/2/201917/6/2026
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
ModificadaAlta (7.8)1.3%—Sony Digital Paper APP4/9/201817/6/2026
Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (8.8)1.6%—Flowpaper Pdf2json5/8/201817/6/2026
An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
ModificadaAlta (8.8)1.6%—Flowpaper Pdf2json5/8/201817/6/2026
An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete).
ModificadaCrítica (9.8)3.1%—Thoughtbot Paperclip13/11/201717/6/2026
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
ModificadaCrítica (9.8)2.6%💥 ExploitGeniusocean Newspaper31/10/201717/6/2026
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
Orbitaley — Vulnerabilidades