Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.77% | — | Lepton-cms Leptoncms | 9/12/2025 | 5/7/2026 | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerability by uploading a specially crafted ZIP/PHP file to execute arbitrary code. | |
| Analizada | Alta (8.8) | 1.3% | — | Lepton-cms Leptoncms | 2/4/2024 | 17/6/2026 | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Alta (8.8) | 1.2% | — | Lepton-cms Leptoncms | 25/3/2024 | 17/6/2026 | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component. | |
| Modificada | Alta (7.8) | 0.42% | — | Lepton-cms Leptoncms | 21/3/2024 | 9/7/2026 | An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place. | |
| Modificada | Alta (7.2) | 16% | — | Lepton-cms Leptoncms | 25/1/2024 | 17/6/2026 | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area. | |
| Modificada | Media (6.1) | 0.51% | — | Lepton-cms Leptoncms | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.32% | — | Lepton Project Lepton | 28/11/2022 | 17/6/2026 | A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service. | |
| Modificada | Media (6.5) | 1.4% | — | Tesseract-ocr Tesseract OCRLeptonicaDebian Linux | 9/9/2022 | 14/9/2026 | An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file. | |
| Modificada | Alta (7.8) | 0.88% | — | Dropbox Lepton | 28/2/2022 | 17/6/2026 | Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108. | |
| Modificada | Alta (7.5) | 2.9% | — | LeptonicaDebian LinuxFedoraproject Fedora | 12/3/2021 | 17/6/2026 | Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. | |
| Modificada | Alta (7.5) | 2.4% | — | LeptonicaFedoraproject Fedora | 12/3/2021 | 17/6/2026 | Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. | |
| Modificada | Alta (7.5) | 2.6% | — | LeptonicaFedoraproject FedoraDebian Linux | 12/3/2021 | 17/6/2026 | Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. | |
| Modificada | Alta (7.5) | 2.9% | — | LeptonicaFedoraproject FedoraDebian Linux | 12/3/2021 | 17/6/2026 | Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. | |
| Modificada | Alta (7.5) | 2.4% | — | LeptonicaFedoraproject FedoraDebian Linux | 11/3/2021 | 17/6/2026 | Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. | |
| Modificada | Media (4.8) | 1.7% | — | Lepton-cms Leptoncms | 2/12/2020 | 17/6/2026 | Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered. | |
| Modificada | Media (6.1) | 1.2% | — | Lepton-cms Lepton CMS | 7/5/2020 | 17/6/2026 | An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements. | |
| Modificada | Media (6.1) | 0.64% | — | Lepton-cms Leptoncms | 7/5/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0. | |
| Modificada | Media (5.5) | 0.96% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file. | |
| Modificada | Alta (7.8) | 0.98% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be… | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 11/6/2018 | 17/6/2026 | An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file. | |
| Modificada | Alta (7.8) | 1.4% | — | LeptonicaDebian Linux | 24/4/2018 | 17/6/2026 | An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to… | |
| Modificada | Crítica (9.1) | 2.0% | — | Leptonica | 23/2/2018 | 17/6/2026 | An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite. | |
| Modificada | Alta (7) | 0.25% | — | Leptonica | 23/2/2018 | 17/6/2026 | Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c. | |
| Modificada | Crítica (9.8) | 3.7% | — | LeptonicaDebian Linux | 23/2/2018 | 17/6/2026 | An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836. | |
| Modificada | Baja (3.3) | 0.42% | — | Leptonica | 23/2/2018 | 17/6/2026 | Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by… |