Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2470 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.52% | 💥 PoC | Qualcomm Libimagecodec.media.quramAI | 10/7/2026 | 10/7/2026 | Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory. | |
| Analizada | Media (4.8) | 0.22% | — | Imagemagick | 8/7/2026 | 9/7/2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure. | |
| Analizada | Baja (2.1) | 0.19% | — | Imagemagick | 8/7/2026 | 10/7/2026 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling… | |
| Analizada | Crítica (9.8) | 0.66% | — | Tonycoz Imager | 8/7/2026 | 10/7/2026 | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could… | |
| Aplazada | Alta (7.5) | 0.61% | — | ImagerAIImager File JpegAI | 6/7/2026 | 6/7/2026 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without… | |
| Aplazada | Alta (7.1) | 0.18% | — | Perl ImagerAI | 6/7/2026 | 6/7/2026 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads… | |
| Aplazada | Crítica (9.8) | 2.8% | 💥 Exploit | Gitea Docker ImageAI | 3/7/2026 | 7/7/2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | |
| Aplazada | Alta (8.5) | 0.36% | — | Nicen-localize-imageAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Shortpixel Adaptive ImagesAI | 2/7/2026 | 2/7/2026 | Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions. | |
| Aplazada | Alta (8.1) | 0.66% | — | Image OptimizerAI | 2/7/2026 | 2/7/2026 | The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they… | |
| Aplazada | Media (5.5) | 0.10% | — | ImagemagickAI | 1/7/2026 | 29/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version… | |
| Analizada | Media (5.5) | 0.10% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26. | |
| Analizada | Media (4.7) | 0.09% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |
| Analizada | Media (5.3) | 0.24% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |
| Analizada | Media (5.9) | 0.23% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and… | |
| Analizada | Media (5.5) | 0.15% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |
| Analizada | Media (5.3) | 0.20% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and… | |
| Analizada | Media (6.5) | 0.22% | — | Imagemagick | 1/7/2026 | 2/7/2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions… | |
| Analizada | Media (4.8) | 0.16% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries. | |
| Analizada | Media (6.3) | 0.23% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images. | |
| Analizada | Media (6.3) | 0.28% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service. | |
| Analizada | Baja (1.8) | 0.15% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of… | |
| Analizada | Media (4.8) | 0.11% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash. | |
| Analizada | Media (4.8) | 0.13% | — | Imagemagick | 30/6/2026 | 2/7/2026 | ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations. | |
| Aplazada | Media (5.1) | 0.34% | — | Ricoh WEB Image MonitorAI | 30/6/2026 | 31/8/2026 | Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL. |