Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.76%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
ModificadaAlta (7.5)0.61%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
AnalizadaCrítica (9.8)0.78%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
AplazadaAlta (7.3)0.56%—TC LIB PDF FontAITcpdfAI27/12/202417/6/2026
An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed.
ModificadaAlta (7.5)0.62%—Tcpdf Project Tcpdf27/12/202417/6/2026
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
ModificadaMedia (6.2)0.81%—Tcpdf Project Tcpdf26/11/202417/6/2026
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.
ModificadaAlta (7.5)1.1%—Tcpdf Project Tcpdf28/5/202417/6/2026
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
ModificadaAlta (7.5)1.3%—Tcpdf Project TcpdfFedoraproject Fedora19/4/202417/6/2026
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
ModificadaMedia (6.1)0.58%—Tcpdf Project Tcpdf15/4/202417/6/2026
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
ModificadaCrítica (9.8)26%—Tecnick TcpdfLimesurvey14/9/201817/6/2026
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
ModificadaAlta (7.5)1.5%—Tcpdf Project Tcpdf23/2/201717/6/2026
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.