Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2470 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.2)0.20%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit29/6/202628/9/2026
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.…
AnalizadaMedia (5.3)0.17%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux29/6/202631/8/2026
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer…
AplazadaMedia (4.3)0.27%—Shoppable Images LiteAI26/6/202626/6/2026
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
AplazadaAlta (7.5)0.43%—Panorama Viewer 360 Degree Image AND Video ViewerAI26/6/202626/6/2026
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
AplazadaMedia (6.5)0.22%—Mer.vin Featured ImageAI26/6/202629/6/2026
Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.
AplazadaMedia (5.8)0.47%—Shortpixel Adaptive ImagesAI26/6/202626/6/2026
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
AplazadaAlta (7.5)0.60%—Faststone Image ViewerAI26/6/202626/6/2026
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
AplazadaMedia (6.5)0.46%—Faststone Image ViewerAI26/6/202626/6/2026
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.
AplazadaMedia (6.5)0.22%—Image CarouselAI26/6/20265/10/2026
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
AnalizadaMedia (4.8)0.18%—Imagemagick24/6/202626/6/2026
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential…
AnalizadaMedia (6.3)0.46%—Imagemagick24/6/202626/6/2026
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
AplazadaMedia (6.1)0.29%—Image Sizes ON DemandAI24/6/202629/6/2026
The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (4.3)0.19%—Bulk SEO ImageAI24/6/202625/6/2026
The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validation on the plugin's settings page handler BulkSeoImage(), which dispatches to launchbulk() / BulkSeoImageGo() whenever the request contains…
ModificadaCrítica (9.2)1.6%—Imagemagick23/6/202615/7/2026
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
AnalizadaMedia (6.3)0.32%—Imagemagick23/6/202624/6/2026
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.
ModificadaMedia (6.9)0.44%—Imagemagick23/6/20262/7/2026
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed.
ModificadaBaja (3.7)0.65%—Openbsd OpensshRedhat Hardened ImagesRedhat Enterprise Linux23/6/202624/9/2026
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving…
ModificadaMedia (6.5)0.60%—Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux23/6/20267/10/2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.…
AnalizadaMedia (6.3)0.39%—Imagemagick21/6/202626/6/2026
ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.
AnalizadaMedia (6.3)0.24%—Imagemagick21/6/202626/6/2026
ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure or a crash.
AnalizadaCrítica (9.1)1.1%💥 PoCMicrosoft Heif Image Extension19/6/20265/10/2026
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer…
AplazadaAlta (8.8)1.1%—Offload AI Optimize With Cloudflare ImagesAI18/6/202618/6/2026
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the…
ModificadaCrítica (9.2)6.5%💥 PoCF5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+717/6/202614/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the…
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
AplazadaAlta (7.2)0.54%—Modula Image GalleryAI15/6/202617/6/2026
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.