Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-56521 | An issue was discovered in TCPDF before 6.8.0. An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-51058 | Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through src tag, potentially exposing sensitive information. NVD description · AI analysis pending | 6.2 | <1% |
| — | ||
| CVE-2024-22641 | TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2024-22640 | TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2024-32489 | TCPDF before 6.7.4 mishandles calls that use HTML syntax. TCPDF before 6.7.4 mishandles calls that use HTML syntax. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2017-6100 | tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP. tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP. NVD description · AI analysis pending | 7.5 | 1% |
| — |