Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.88% | — | Artifex Ghostscript | 4/2/2024 | 17/6/2026 | Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature). | |
| Modificada | Media (5.4) | 0.33% | — | Jhayghost Ideal Interactive MAP | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This issue affects Ideal Interactive Map: from n/a through 1.2.4. | |
| Modificada | Media (6.1) | 0.44% | — | Ghost | 21/1/2024 | 17/6/2026 | Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries. | |
| Modificada | Alta (7.5) | 1.5% | — | Artifex Ghostscript | 6/12/2023 | 17/6/2026 | An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer. | |
| Modificada | Alta (8.8) | 6.0% | 💥 PoC | Artifex GhostscriptFedoraproject Fedora | 18/9/2023 | 17/6/2026 | In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs… | |
| Modificada | Media (5.5) | 0.34% | — | Artifex GhostscriptRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 23/8/2023 | 17/6/2026 | A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. | |
| Modificada | Alta (7.8) | 0.81% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document. | |
| Modificada | Media (5.5) | 0.70% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file. | |
| Modificada | Media (6.5) | 69% | 💥 Exploit | Ghost | 15/8/2023 | 17/6/2026 | Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation… | |
| Modificada | Media (5.5) | 0.32% | — | Artifex Ghostscript | 1/8/2023 | 17/6/2026 | An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format. | |
| Modificada | Media (5.5) | 0.43% | — | Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 1/8/2023 | 23/6/2026 | A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs. | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Artifex GhostscriptDebian LinuxFedoraproject Fedora | 25/6/2023 | 28/8/2026 | Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). | |
| Modificada | Alta (7.8) | 0.40% | — | Cyberghostvpn Cyberghost | 9/5/2023 | 9/7/2026 | CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe. | |
| Modificada | Media (6.5) | 0.32% | — | Wpplugins Hide MY WP Ghost | 9/5/2023 | 17/6/2026 | The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For… | |
| Modificada | Alta (7.5) | 46% | — | Ghost | 8/5/2023 | 17/6/2026 | Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid subscriptions to members. Prior to version 5.46.1, due to a lack of validation when filtering on the public API endpoints, it is possible to reveal private fields via a brute force attack. Ghost(Pro)… | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Ghost | 5/5/2023 | 17/6/2026 | Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js. | |
| Modificada | Media (5.5) | 0.32% | — | Ghost Sqlite3 | 11/4/2023 | 17/6/2026 | Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script. | |
| Modificada | Crítica (9.8) | 6.3% | — | Artifex GhostscriptDebian Linux | 31/3/2023 | 17/6/2026 | In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an… | |
| Modificada | Crítica (9.8) | 2.4% | — | Ghost Sqlite3 | 16/3/2023 | 17/6/2026 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability. | |
| Modificada | Media (5.7) | 0.63% | — | Ghost | 5/3/2023 | 17/6/2026 | Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact. | |
| Modificada | Media (5.4) | 1.0% | — | Ghost | 19/1/2023 | 17/6/2026 | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can… | |
| Modificada | Media (5.4) | 0.68% | — | Ghost | 19/1/2023 | 17/6/2026 | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can… | |
| Modificada | Media (5.4) | 0.68% | — | Ghost | 19/1/2023 | 17/6/2026 | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can… | |
| Modificada | Media (5.4) | 0.82% | — | Ghost | 19/1/2023 | 17/6/2026 | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can… | |
| Modificada | Media (5.3) | 20% | 💥 Exploit | Ghost | 22/12/2022 | 17/6/2026 | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability. |