Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.27%—GpsdAIGnuplotAI23/7/202630/7/2026
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot…
AnalizadaAlta (8.1)0.43%—Plotly.js Graphing10/7/202614/7/2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
AnalizadaMedia (5.6)0.34%—Debian Matplotlib26/6/202516/6/2026
Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.
AnalizadaAlta (7.5)0.50%—Ricko Brplot20/6/202517/6/2026
brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
ModificadaMedia (5.5)0.20%—Gnuplot7/5/202526/6/2026
gnuplot is affected by a heap buffer overflow at function utf8_copy_one.
AplazadaMedia (6.2)0.20%—GnuplotAI7/4/202517/6/2026
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.
ModificadaCrítica (9.3)1.0%—Mljar Plotai10/3/202517/6/2026
A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor…
AplazadaAlta (7.8)0.70%—UplotAI1/10/202410/8/2026
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
ModificadaMedia (5.4)1.5%—Plotly Dash2/2/202417/6/2026
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting…
ModificadaCrítica (9.8)0.94%—Plotly.js3/1/202417/6/2026
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
ModificadaMedia (4.8)0.39%—Stpetedesign GPS Plotter17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.1.4 versions.
ModificadaCrítica (9.8)1.0%—Gnuplot5/7/202317/6/2026
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
ModificadaCrítica (9.8)1.1%—Stoqey Gnuplot10/3/202317/6/2026
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
ModificadaCrítica (9.8)0.97%—Jenkins Plot12/12/202217/6/2026
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.4)81%—Jenkins Plot30/6/202217/6/2026
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (8.1)1.0%—Jenkins Coverage/complexity Scatter Plot29/3/202217/6/2026
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.5)0.70%—Gnuplot21/12/202117/6/2026
A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.
ModificadaCrítica (9.8)1.8%—Gnuplot Project Gnuplot3/5/202117/6/2026
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.
ModificadaMedia (5.4)0.73%—Jenkins Coverage/complexity Scatter Plot16/9/202017/6/2026
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
ModificadaCrítica (9.8)2.6%—Gnuplot16/9/202017/6/2026
com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.