Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 19% | — | Ghost | 22/12/2022 | 17/6/2026 | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.1) | 0.46% | — | Artifex GhostscriptDebian Linux | 19/8/2022 | 17/6/2026 | A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptFedoraproject Fedora | 16/6/2022 | 17/6/2026 | A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64,… | |
| Modificada | Alta (7.5) | 2.2% | — | Ghost Sqlite3 | 1/5/2022 | 17/6/2026 | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine. | |
| Modificada | Alta (7.8) | 1.2% | — | Artifex GhostscriptDebian Linux | 25/4/2022 | 17/6/2026 | Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839. | |
| Modificada | Alta (7.8) | 0.84% | — | Artifex Ghostpcl | 14/4/2022 | 17/6/2026 | A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.5% | — | Ghost | 12/4/2022 | 9/7/2026 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional. | |
| Modificada | Crítica (9.8) | 4.0% | — | Ghost | 12/4/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's security documentation, upload of SVGs is only possible by trusted authenticated users. The uploading of SVG files to… | |
| Modificada | Crítica (9.9) | 84% | — | Artifex GhostscriptFedoraproject Fedora | 16/2/2022 | 17/6/2026 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this… | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 1/1/2022 | 17/6/2026 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptDebian Linux | 1/1/2022 | 17/6/2026 | Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp). | |
| Modificada | Alta (7.2) | 1.0% | — | Ghost | 3/9/2021 | 17/6/2026 | Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authenticated users (including contributors) to view admin-level API keys via the integrations API endpoint, leading to a privilege escalation vulnerability. This issue is… | |
| Modificada | Media (6.1) | 7.9% | 💥 Exploit | Ghost | 29/4/2021 | 17/6/2026 | Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've… | |
| Modificada | Crítica (9.8) | 2.9% | — | Ghost Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Media (5.5) | 0.45% | — | Artifex GhostscriptRedhat Enterprise Linux | 3/9/2020 | 17/6/2026 | A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.3% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Analizada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51. | |
| Modificada | Alta (7.8) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51. |