Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (6.3) | 0.24% | — | ImagerAI | 1/10/2026 | 1/10/2026 | Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with type "float" allocates a buffer of one sample per pixel and fetches every requested channel of each pixel into it. Requesting more than one channel writes… | |
| En análisis | Alta (7.5) | 0.39% | — | ImagerAI | 1/10/2026 | 1/10/2026 | Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an… | |
| Aplazada | Crítica (9.1) | 0.65% | — | ImagerAI | 18/9/2026 | 18/9/2026 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more becomes negative. tga_palette_read() casts that value to size_t and asks mymalloc() for… | |
| Aplazada | Media (5.5) | 0.18% | — | Perl ImagerAI | 18/9/2026 | 22/9/2026 | Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them… | |
| Aplazada | Crítica (9.1) | 0.70% | — | ImagerAIPerl Imager File PNGAI | 17/9/2026 | 22/9/2026 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands… | |
| Aplazada | Media (6.2) | 0.19% | — | ImagerAI | 17/9/2026 | 22/9/2026 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the EXIF block, and never checks the start offset itself. Where that sum is not the real… | |
| Aplazada | Media (6.8) | 0.20% | — | Exterro FTK ImagerAI | 3/9/2026 | 14/9/2026 | Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item.… | |
| Aplazada | Alta (7.5) | 0.51% | — | Perl ImagerAI | 7/8/2026 | 26/8/2026 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count ASCII entry sets `entry->size` to 0, and… | |
| Analizada | Crítica (9.8) | 0.66% | — | Tonycoz Imager | 8/7/2026 | 10/7/2026 | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could… | |
| Aplazada | Alta (7.5) | 0.61% | — | ImagerAIImager File JpegAI | 6/7/2026 | 6/7/2026 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without… | |
| Aplazada | Alta (7.1) | 0.18% | — | Perl ImagerAI | 6/7/2026 | 6/7/2026 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit sample consumes two bytes. The copy loop reads… | |
| Aplazada | Media (6.5) | 0.36% | — | Perl ImagerAI | 15/5/2026 | 17/6/2026 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match branch validates… | |
| Analizada | Media (5.3) | 0.19% | — | Tonyc Imager\ | 15/5/2026 | 17/6/2026 | Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file. The page-match… | |
| Aplazada | Media (5.4) | 0.28% | — | Merkulove Comparimager FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.26% | — | Merkulove Imager FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in merkulove Imager for Elementor imager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Imager for Elementor: from n/a through <= 2.0.4. | |
| Aplazada | Media (6.8) | 0.16% | — | Raspberrypi ImagerAI | 3/11/2025 | 17/6/2026 | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes… | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Imagerating ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ImageRating Extension allows Stored XSS.This issue affects Mediawiki - ImageRating Extension: from master before 1.39. | |
| Analizada | Crítica (9.8) | 0.88% | — | Canon Satera Mf656cdw FirmwareCanon Satera Mf654cdw FirmwareCanon Satera Mf551dw FirmwareCanon Satera Mf457dw Firmware+33 | 26/5/2025 | 17/6/2026 | Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw… | |
| Modificada | Media (6.1) | 0.44% | — | Imagerecycle PDF & Image Compression | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression imagerecycle-pdf-image-compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through <= 3.1.16. | |
| Analizada | Media (5.5) | 0.39% | — | Tonycoz Imager | 24/11/2024 | 17/6/2026 | The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. | |
| Analizada | Media (4.3) | 0.19% | — | Imagerecycle PDF & Image Compression | 24/8/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.26% | — | Imagerecycle PDF & Image Compression | 24/8/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possible for unauthenticated attackers to remove all plugin data via a… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the stopOptimizeAll function. This makes it possible for unauthenticated attackers to modify image optimization… | |
| Modificada | Media (4.3) | 0.21% | — | Imagerecycle PDF & Image Compression | 29/2/2024 | 17/6/2026 | The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the optimizeAllOn function. This makes it possible for unauthenticated attackers to modify image optimization… |