Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
193 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) . | |
| Modificada | Media (5.5) | 0.66% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 . | |
| Modificada | Media (5.5) | 0.63% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 . | |
| Modificada | Media (5.5) | 0.74% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . | |
| Modificada | Media (5.5) | 0.74% | — | Flowpaper Pdf2json | 21/7/2021 | 17/6/2026 | An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow. | |
| Modificada | Media (6.1) | 0.83% | — | Tagdiv Newspaper | 19/7/2021 | 17/6/2026 | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call. | |
| Modificada | Alta (7.8) | 0.54% | — | Flowpaper Pdf2json | 5/2/2021 | 17/6/2026 | Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file. | |
| Modificada | Media (6.1) | 1.6% | — | Papermerge | 2/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. The payload can be in a folder, a tag, or a document's filename. If email consumption is configured in Papermerge, a… | |
| Modificada | Media (6.1) | 9.2% | 💥 Exploit | Graphpaperpress Sell Media | 14/8/2020 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field). | |
| Modificada | Crítica (9.8) | 1.8% | — | Papercrop Project Papercrop | 21/1/2020 | 17/6/2026 | The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo Paper | 20/11/2019 | 17/6/2026 | A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation. | |
| Modificada | Media (6.1) | 1.1% | — | Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper | 22/10/2019 | 17/6/2026 | The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js. | |
| Modificada | Crítica (9.8) | 9.3% | 💥 Exploit | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | |
| Modificada | Crítica (9.8) | 2.2% | — | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Flowpaper Flexpaper | 3/7/2019 | 17/6/2026 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Papercut MFPapercut NG | 6/6/2019 | 17/6/2026 | An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector. | |
| Modificada | Alta (7.8) | 2.6% | 💥 Exploit | Fujitsu Paperstream IP (twain) | 17/5/2019 | 17/6/2026 | In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported… | |
| Modificada | Crítica (9.8) | 3.9% | — | Papercut MFPapercut NG | 20/2/2019 | 17/6/2026 | PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. | |
| Modificada | Alta (7.8) | 1.3% | — | Sony Digital Paper APP | 4/9/2018 | 17/6/2026 | Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (8.8) | 1.6% | — | Flowpaper Pdf2json | 5/8/2018 | 17/6/2026 | An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete). | |
| Modificada | Alta (8.8) | 1.6% | — | Flowpaper Pdf2json | 5/8/2018 | 17/6/2026 | An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete). | |
| Modificada | Crítica (9.8) | 3.1% | — | Thoughtbot Paperclip | 13/11/2017 | 17/6/2026 | Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Geniusocean Newspaper | 31/10/2017 | 17/6/2026 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. |