Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%💥 ExploitReamday Enterprises Magic News Plus10/1/200616/6/2026
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.
ModificadaMedia (5.1)4.3%—Imagemagick4/1/200616/6/2026
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of…
ModificadaAlta (7.5)3.7%—Imagemagick31/12/200516/6/2026
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
ModificadaMedia (4.3)1.9%💥 ExploitCfmagic Magic Book PersonalCfmagic Magic Book Professional12/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter.
ModificadaAlta (7.5)1.1%💥 ExploitCfmagic Magic List PRO8/12/200516/6/2026
SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.
ModificadaAlta (7.5)1.3%💥 ExploitCfmagic Magic Forum Personal8/12/200516/6/2026
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.
ModificadaMedia (4.3)1.2%—Cfmagic Magic Forum Personal8/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum Personal 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the Words parameter in search_forums.cfm, as used in the "Search For:" field.
ModificadaMedia (5)7.3%💥 ExploitAmax Information Technologies Magic Winmail Server25/11/200516/6/2026
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.
ModificadaMedia (4.3)2.1%—Amax Information Technologies Magic Winmail Server19/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments.
ModificadaAlta (7.2)0.39%—Imagemagick16/11/200516/6/2026
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
ModificadaMedia (5)4.2%—GraphicsmagickImagemagick24/5/200516/6/2026
The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.
ModificadaAlta (7.5)4.2%—Imagemagick2/5/200516/6/2026
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web…
ModificadaAlta (7.5)1.5%—Magicscripts E-store Kit-22/5/200516/6/2026
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.
ModificadaMedia (5)1.7%—Imagemagick2/5/200516/6/2026
The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.
ModificadaAlta (7.5)4.4%—GraphicsmagickImagemagickSGI PropackDebian Linux+22/5/200516/6/2026
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
ModificadaAlta (7.5)3.4%—Imagemagick2/5/200516/6/2026
Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.
ModificadaMedia (5)14%💥 ExploitGraphicsmagickImagemagick25/4/200516/6/2026
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.
ModificadaMedia (4.3)1.0%—Magicscripts E-store Kit-226/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.
ModificadaMedia (5)1.8%—ImagemagickSGI Propack23/3/200516/6/2026
ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag.
ModificadaMedia (5)1.7%—ImagemagickSGI Propack23/3/200516/6/2026
Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cause a denial of service (application crash) via a crafted PSD file.
ModificadaAlta (10)5.8%—ImagemagickDebian LinuxGentoo LinuxSuse Linux9/2/200516/6/2026
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
ModificadaMedia (4.3)1.2%—Magicwinmail Winmail ServerAI27/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.
ModificadaAlta (7.5)3.4%💥 ExploitAmax Information Technologies Magic Winmail Server27/1/200516/6/2026
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary…
ModificadaMedia (4.6)0.75%—Amax Information Technologies Magic Winmail Server27/1/200516/6/2026
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
ModificadaMedia (5.1)3.4%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.