Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 28 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.61% | — | ExifreaderAI | 17/9/2026 | 30/9/2026 | ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc itemCount and extentCount values while allocating an extent object for every nested-loop iteration. When… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | ExifreaderAI | 14/9/2026 | 30/9/2026 | ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight-byte box header without confirming… | |
| Aplazada | Baja (2.9) | 0.15% | — | TinyexifAI | 13/9/2026 | 22/9/2026 | TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length. | |
| Aplazada | Media (5.5) | 0.51% | — | ExifreaderAI | 19/5/2026 | 23/7/2026 | Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly… | |
| Aplazada | Alta (7.7) | 0.61% | — | ExifreaderAI | 19/5/2026 | 23/7/2026 | This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation,… | |
| Aplazada | Alta (8.2) | 0.53% | — | Exiftool VendoredAIExiftoolAI | 11/5/2026 | 17/6/2026 | exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments without rejecting… | |
| Aplazada | Baja (1.9) | 0.20% | — | ExiftoolAI | 1/5/2026 | 17/6/2026 | A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading to version 13.54 is recommended to… | |
| Analizada | Alta (7.1) | 0.13% | — | Libexif Project Libexif | 12/4/2026 | 17/6/2026 | In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs. | |
| Analizada | Alta (7.1) | 0.13% | — | Libexif Project Libexif | 12/4/2026 | 17/6/2026 | In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems. | |
| Analizada | Alta (8.6) | 0.45% | — | Lexiforest Curl Cffi | 6/4/2026 | 17/6/2026 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpoints. In addition,… | |
| Analizada | Alta (7.8) | 0.16% | — | Libexif Project Libexif | 16/3/2026 | 17/6/2026 | libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow. | |
| Analizada | Baja (2.1) | 2.8% | — | Exiftool Project Exiftool | 24/2/2026 | 17/6/2026 | A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (6.1) | 0.36% | — | Exif Viewer ClassicAI | 29/1/2025 | 17/6/2026 | The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed on the web browser. Versions 2.3.2 and 2.4.0 were reported as vulnerable. According… | |
| Analizada | Alta (7.8) | 0.28% | — | Aertherwide Exiftags | 27/8/2024 | 17/6/2026 | Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function. | |
| Modificada | Alta (7.8) | 0.36% | — | Aertherwide Exiftags | 11/1/2024 | 17/6/2026 | In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address. | |
| Modificada | Media (4.8) | 0.36% | — | Kristarella Exifography | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Exifography plugin <= 1.3.1 versions. | |
| Modificada | Alta (7.8) | 7.6% | — | Exiftool Project Exiftool | 25/1/2022 | 17/6/2026 | lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa | Exiftool Project ExiftoolDebian LinuxFedoraproject Fedora | 23/4/2021 | 17/6/2026 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | |
| Modificada | Media (5.5) | 1.3% | — | Libexif Project ExifFedoraproject Fedora | 14/4/2021 | 17/6/2026 | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash. | |
| Modificada | Media (6.5) | 1.5% | — | Kamadak-exif Project Kamadak-exif | 6/1/2021 | 17/6/2026 | kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. Specifically, reader::read_from_container can cause an infinite loop when a crafted PNG file is given. This is fixed in version 0.5.3. No workaround is available.… | |
| Modificada | Alta (7.5) | 4.3% | — | Google AndroidLibexif Project LibexifCanonical Ubuntu LinuxDebian Linux+1 | 11/6/2020 | 17/6/2026 | In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941 | |
| Modificada | Alta (7.5) | 2.9% | — | Google AndroidLibexif Project LibexifFedoraproject Fedora | 11/6/2020 | 17/6/2026 | In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076 | |
| Modificada | Alta (8.2) | 1.9% | — | Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. | |
| Modificada | Alta (7.5) | 2.3% | — | Libexif Project LibexifCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data. | |
| Modificada | Crítica (9.1) | 2.7% | — | Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093. |