Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.27% | — | GpsdAIGnuplotAI | 23/7/2026 | 30/7/2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot… | |
| Analizada | Alta (8.1) | 0.43% | — | Plotly.js Graphing | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2. | |
| Analizada | Media (5.6) | 0.34% | — | Debian Matplotlib | 26/6/2025 | 16/6/2026 | Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787. | |
| Analizada | Alta (7.5) | 0.50% | — | Ricko Brplot | 20/6/2025 | 17/6/2026 | brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes. | |
| Modificada | Media (5.5) | 0.20% | — | Gnuplot | 7/5/2025 | 26/6/2026 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. | |
| Aplazada | Media (6.2) | 0.20% | — | GnuplotAI | 7/4/2025 | 17/6/2026 | A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Crítica (9.3) | 1.0% | — | Mljar Plotai | 10/3/2025 | 17/6/2026 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor… | |
| Aplazada | Alta (7.8) | 0.70% | — | UplotAI | 1/10/2024 | 10/8/2026 | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype. | |
| Modificada | Media (5.4) | 1.5% | — | Plotly Dash | 2/2/2024 | 17/6/2026 | Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting… | |
| Modificada | Crítica (9.8) | 0.94% | — | Plotly.js | 3/1/2024 | 17/6/2026 | In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty. | |
| Modificada | Media (4.8) | 0.39% | — | Stpetedesign GPS Plotter | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gnuplot | 5/7/2023 | 17/6/2026 | gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). | |
| Modificada | Crítica (9.8) | 1.1% | — | Stoqey Gnuplot | 10/3/2023 | 17/6/2026 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | |
| Modificada | Crítica (9.8) | 0.97% | — | Jenkins Plot | 12/12/2022 | 17/6/2026 | Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.4) | 81% | — | Jenkins Plot | 30/6/2022 | 17/6/2026 | Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.1) | 1.0% | — | Jenkins Coverage/complexity Scatter Plot | 29/3/2022 | 17/6/2026 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.5) | 0.70% | — | Gnuplot | 21/12/2021 | 17/6/2026 | A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gnuplot Project Gnuplot | 3/5/2021 | 17/6/2026 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Coverage/complexity Scatter Plot | 16/9/2020 | 17/6/2026 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step. | |
| Modificada | Crítica (9.8) | 2.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. |