Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
1700 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (4.3) | — | — | Farvisun Mindio Magic MCPAI | 4/10/2026 | 4/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6. | |
| Recibida | Alta (7.2) | 0.32% | — | Magic Tooltips FOR Contact Form 7AI | 3/10/2026 | 3/10/2026 | The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Recibida | Baja (1.8) | 0.12% | — | ImagemagickAI | 3/10/2026 | 3/10/2026 | ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | GraphicsmagickAI | 30/9/2026 | 2/10/2026 | A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2.… | |
| Pendiente de análisis | Media (6.3) | 0.32% | — | ImagemagickAI | 29/9/2026 | 30/9/2026 | ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing… | |
| Pendiente de análisis | Media (6.3) | 0.31% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory… | |
| Pendiente de análisis | Media (6.3) | 0.29% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56. | |
| Pendiente de análisis | Baja (2.3) | 0.26% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application… | |
| Pendiente de análisis | Media (4.8) | 0.11% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass… | |
| Pendiente de análisis | Baja (2.1) | 0.11% | — | ImagemagickAI | 18/9/2026 | 22/9/2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56. | |
| Aplazada | Alta (8.8) | 0.76% | — | Laravel MagiclinkAI | 14/9/2026 | 30/9/2026 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient… | |
| Aplazada | Baja (2) | 2.2% | — | Magicblack Maccms10AI | 14/9/2026 | 16/9/2026 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command… | |
| Aplazada | Alta (8.7) | 2.7% | — | FilerunAIImagemagickAI | 10/9/2026 | 10/9/2026 | FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command substitution syntax such… | |
| Analizada | Media (4.8) | 0.15% | — | Imagemagick | 7/9/2026 | 9/9/2026 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service). | |
| Analizada | Media (4.8) | 0.11% | — | Imagemagick | 7/9/2026 | 9/9/2026 | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service). | |
| Analizada | Baja (1) | 0.13% | — | Imagemagick | 7/9/2026 | 10/9/2026 | ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied… | |
| Analizada | Media (6.3) | 0.45% | — | Imagemagick | 7/9/2026 | 9/9/2026 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service. | |
| Analizada | Media (6.3) | 0.32% | — | Imagemagick | 7/9/2026 | 9/9/2026 | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service. | |
| Analizada | Baja (2) | 0.14% | — | Imagemagick | 7/9/2026 | 19/9/2026 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time)… | |
| Aplazada | Alta (8.8) | 0.41% | — | Metagauss RegistrationmagicAI | 5/9/2026 | 8/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user… | |
| Aplazada | Media (5.3) | 0.32% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants. | |
| Aplazada | Media (5.3) | 0.32% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account. | |
| Aplazada | Alta (7.5) | 0.37% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | |
| Aplazada | Alta (7.4) | 0.39% | — | Metagauss RegistrationmagicAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Registrationmagic Registration MagicAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. |