Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.10% | — | Intel Neural Compressor | 11/8/2026 | 31/8/2026 | Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Media (5.4) | 0.16% | — | Intel Neural Compressor | 11/8/2026 | 28/9/2026 | Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Lymphatus Caesium-image-compressorAI | 4/5/2026 | 17/6/2026 | An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp | |
| Analizada | Media (6.3) | 0.53% | — | Airlift Aircompressor | 12/12/2025 | 1/10/2026 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed… | |
| Analizada | Alta (8.8) | 0.28% | — | Apple Compressor | 13/11/2025 | 17/6/2026 | The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a Compressor server may be able to execute arbitrary code. | |
| Aplazada | Baja (2.4) | 0.12% | — | Intel Neural CompressorAI | 11/11/2025 | 17/6/2026 | Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (7.1) | 0.21% | — | Regen Script CompressorAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in regen Script Compressor script-compressor allows Stored XSS.This issue affects Script Compressor: from n/a through <= 1.7.1. | |
| Analizada | Media (5.1) | 0.39% | — | Rems Image Compressor Tool | 11/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The manipulation of the argument image leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.13% | — | Intel Neural CompressorAI | 16/1/2025 | 17/6/2026 | Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access. | |
| Aplazada | Alta (7.3) | 0.23% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.6) | 0.34% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Media (5.1) | 0.26% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Aplazada | Alta (7.7) | 0.31% | — | Intel Neural CompressorAI | 13/11/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (4.3) | 0.32% | — | Himalayasaxena Highcompress Image Compressor | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0. | |
| Aplazada | Alta (8.6) | 0.50% | — | Airlift AircompressorAI | 29/5/2024 | 17/6/2026 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompressor implementations of Aircompressor (LZ4, LZO, Snappy, Zstandard) can crash the JVM for certain input, and in some cases also leak the content of other memory of the Java process (which could… | |
| Aplazada | Crítica (10) | 36% | — | Intel Neural CompressorAI | 16/5/2024 | 17/6/2026 | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access. | |
| Aplazada | Media (4.7) | 0.14% | — | Intel Neural CompressorAI | 16/5/2024 | 17/6/2026 | Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 1.1% | — | Deepin-compressor | 27/12/2023 | 17/6/2026 | Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to update to version 5.12.21 which addresses… | |
| Modificada | Crítica (9.8) | 0.81% | — | Johnsoncontrols Quantum HD Unity Compressor FirmwareJohnsoncontrols Quantum HD Unity Acuair FirmwareJohnsoncontrols Quantum HD Unity Condenser/vessel FirmwareJohnsoncontrols Quantum HD Unity Evaporator Firmware+2 | 10/11/2023 | 17/6/2026 | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. | |
| Modificada | Alta (7.8) | 1.6% | — | Jpeg-compressor Project Jpeg Compressor | 1/7/2018 | 17/6/2026 | An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 1.6% | — | Jpeg-compressor Project Jpeg Compressor | 30/6/2018 | 17/6/2026 | An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 3.3% | — | Foxitsoftware PDF Compressor | 16/8/2017 | 17/6/2026 | Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. | |
| Modificada | Media (6.4) | 6.0% | — | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter. |