Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.39% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution. | |
| Analizada | Alta (7.8) | 0.32% | — | Artifex GhostscriptDebian Linux | 10/11/2024 | 17/6/2026 | An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values). | |
| Modificada | Alta (7.8) | 0.36% | — | Artifex GhostscriptDebian LinuxSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Server+1 | 10/11/2024 | 17/6/2026 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. | |
| Aplazada | Media (6.4) | 0.32% | — | Davidartiss Code EmbedAI | 9/11/2024 | 17/6/2026 | The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web… | |
| Analizada | Media (5.3) | 0.40% | — | Martinvalchev Video Gallery FOR Woocommerce | 6/11/2024 | 17/6/2026 | The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the… | |
| Aplazada | Alta (8.2) | 0.25% | — | Fireboltt Artillery Smart Watch Nj-r6e-10.3AI | 8/10/2024 | 17/6/2026 | Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS). | |
| Aplazada | Alta (7.1) | 0.32% | — | Ays-pro ChartifyAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify chart-builder allows Reflected XSS.This issue affects Chartify: from n/a through <= 2.7.6. | |
| Aplazada | Alta (7.5) | 0.56% | — | Martin Greenwood WpspxAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX wpspx allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through <= 1.0.2. | |
| Analizada | Media (5.4) | 0.26% | — | Davidartiss Code Embed | 4/10/2024 | 17/6/2026 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with contributor-level access… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Github Actions/artifactGithub Actions Toolkit | 2/9/2024 | 17/6/2026 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that… | |
| Analizada | Crítica (9.8) | 0.63% | — | Chartist | 29/8/2024 | 17/6/2026 | Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Xnau Participants DatabaseAI | 13/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2. | |
| Aplazada | Crítica (9.3) | 0.60% | — | Jfrog ArtifactoryAI | 5/8/2024 | 17/6/2026 | JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning. | |
| Modificada | Media (6.1) | 0.31% | — | Artistscope Copysafe WEB Protection | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Reflected XSS.This issue affects CopySafe Web Protection: from n/a through 3.15. | |
| Modificada | Media (5.4) | 0.31% | — | Artistscope Copysafe WEB Protection | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Stored XSS.This issue affects CopySafe Web Protection: from n/a through 3.14. | |
| Modificada | Alta (8.8) | 0.68% | — | Elearningfreak Insert OR Embed Articulate Content | 15/7/2024 | 17/6/2026 | The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites. | |
| Modificada | Media (6.1) | 0.33% | — | Dj-extensions Dj-helpfularticles | 9/7/2024 | 17/6/2026 | XSS vulnerability in DJ-HelpfulArticles component for Joomla. | |
| Analizada | Alta (8.8) | 1.4% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this… | |
| Analizada | Media (6.3) | 0.52% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted. | |
| Analizada | Media (5.3) | 0.45% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename. | |
| Analizada | Alta (7.5) | 1.1% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd. | |
| Analizada | Media (6.3) | 28% | 💥 Exploit | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. | |
| Analizada | Media (5.4) | 0.72% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters. | |
| Modificada | Alta (8.8) | 1.4% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle. | |
| Modificada | Baja (3.3) | 0.38% | — | Artifex Ghostscript | 3/7/2024 | 17/6/2026 | Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc. |