Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

1700 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (4.3)——Farvisun Mindio Magic MCPAI4/10/20264/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6.
RecibidaAlta (7.2)0.32%—Magic Tooltips FOR Contact Form 7AI3/10/20263/10/2026
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
RecibidaBaja (1.8)0.12%—ImagemagickAI3/10/20263/10/2026
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted…
Pendiente de análisisMedia (5.3)0.29%—GraphicsmagickAI30/9/20262/10/2026
A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.…
Pendiente de análisisMedia (6.3)0.32%—ImagemagickAI29/9/202630/9/2026
ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing…
Pendiente de análisisMedia (6.3)0.31%—ImagemagickAI18/9/202622/9/2026
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory…
Pendiente de análisisMedia (6.3)0.29%—ImagemagickAI18/9/202622/9/2026
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Pendiente de análisisBaja (2.3)0.26%—ImagemagickAI18/9/202622/9/2026
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application…
Pendiente de análisisMedia (4.8)0.11%—ImagemagickAI18/9/202622/9/2026
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass…
Pendiente de análisisBaja (2.1)0.11%—ImagemagickAI18/9/202622/9/2026
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.
AplazadaAlta (8.8)0.76%—Laravel MagiclinkAI14/9/202630/9/2026
Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient…
AplazadaBaja (2)2.2%—Magicblack Maccms10AI14/9/202616/9/2026
A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command…
AplazadaAlta (8.7)2.7%—FilerunAIImagemagickAI10/9/202610/9/2026
FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command substitution syntax such…
AnalizadaMedia (4.8)0.15%—Imagemagick7/9/20269/9/2026
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).
AnalizadaMedia (4.8)0.11%—Imagemagick7/9/20269/9/2026
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).
AnalizadaBaja (1)0.13%—Imagemagick7/9/202610/9/2026
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied…
AnalizadaMedia (6.3)0.45%—Imagemagick7/9/20269/9/2026
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.
AnalizadaMedia (6.3)0.32%—Imagemagick7/9/20269/9/2026
ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.
AnalizadaBaja (2)0.14%—Imagemagick7/9/202619/9/2026
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time)…
AplazadaAlta (8.8)0.41%—Metagauss RegistrationmagicAI5/9/20268/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user…
AplazadaMedia (5.3)0.32%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
AplazadaMedia (5.3)0.32%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
AplazadaAlta (7.5)0.37%—Metagauss RegistrationmagicAI2/9/20263/9/2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
AplazadaAlta (7.4)0.39%—Metagauss RegistrationmagicAI31/8/20261/9/2026
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
AplazadaAlta (7.1)0.25%—Registrationmagic Registration MagicAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.