Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.27% | — | GpsdAIGnuplotAI | 23/7/2026 | 30/7/2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot… | |
| Modificada | Media (5.5) | 0.20% | — | Gnuplot | 7/5/2025 | 26/6/2026 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. | |
| Aplazada | Media (6.2) | 0.20% | — | GnuplotAI | 7/4/2025 | 17/6/2026 | A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Media (6.2) | 0.19% | — | Gnuplot | 27/3/2025 | 26/6/2026 | A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gnuplot | 5/7/2023 | 17/6/2026 | gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). | |
| Modificada | Crítica (9.8) | 1.1% | — | Stoqey Gnuplot | 10/3/2023 | 17/6/2026 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | |
| Modificada | Media (5.5) | 0.70% | — | Gnuplot | 21/12/2021 | 17/6/2026 | A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gnuplot Project Gnuplot | 3/5/2021 | 17/6/2026 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | |
| Modificada | Crítica (9.8) | 2.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo… | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript… | |
| Modificada | Alta (7.8) | 1.8% | — | GnuplotDebian LinuxOpensuse Leap | 23/11/2018 | 17/6/2026 | An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is… | |
| Modificada | Alta (7.8) | 0.87% | — | Gnuplot | 15/6/2017 | 17/6/2026 | An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file. | |
| Modificada | Alta (7.2) | 0.47% | — | Gnuplot | 31/12/2002 | 16/6/2026 | Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors. |