Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.76% | — | Tcpdf Project Tcpdf | 27/12/2024 | 17/6/2026 | An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message. | |
| Modificada | Alta (7.5) | 0.61% | — | Tcpdf Project Tcpdf | 27/12/2024 | 17/6/2026 | An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes. | |
| Analizada | Crítica (9.8) | 0.78% | — | Tcpdf Project Tcpdf | 27/12/2024 | 17/6/2026 | An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely. | |
| Aplazada | Alta (7.3) | 0.56% | — | TC LIB PDF FontAITcpdfAI | 27/12/2024 | 17/6/2026 | An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed. | |
| Modificada | Alta (7.5) | 0.62% | — | Tcpdf Project Tcpdf | 27/12/2024 | 17/6/2026 | An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute. | |
| Modificada | Media (6.2) | 0.81% | — | Tcpdf Project Tcpdf | 26/11/2024 | 17/6/2026 | Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information. | |
| Modificada | Alta (7.5) | 1.1% | — | Tcpdf Project Tcpdf | 28/5/2024 | 17/6/2026 | TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. | |
| Modificada | Alta (7.5) | 1.3% | — | Tcpdf Project TcpdfFedoraproject Fedora | 19/4/2024 | 17/6/2026 | TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. | |
| Modificada | Media (6.1) | 0.58% | — | Tcpdf Project Tcpdf | 15/4/2024 | 17/6/2026 | TCPDF before 6.7.4 mishandles calls that use HTML syntax. | |
| Modificada | Crítica (9.8) | 26% | — | Tecnick TcpdfLimesurvey | 14/9/2018 | 17/6/2026 | An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | |
| Modificada | Alta (7.5) | 1.5% | — | Tcpdf Project Tcpdf | 23/2/2017 | 17/6/2026 | tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP. |