Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.1% | — | Advantech Webaccess HMI Designer | 2/8/2019 | 17/6/2026 | In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution. | |
| Modificada | Alta (7.5) | 2.0% | — | Fatek Automation FV DesignerFatek Automation PM Designer V3 | 21/3/2019 | 17/6/2026 | A malicious attacker can trigger a remote buffer overflow in the Communication Server in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. | |
| Modificada | Alta (7.5) | 1.7% | — | SAP Financial Consolidation Cube DesignerSAP Financial Consolidation Cube Designer Bobj Eades | 8/1/2019 | 17/6/2026 | A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user. | |
| Modificada | Crítica (10) | 1.8% | — | Obeo UML Designer | 20/12/2018 | 17/6/2026 | UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file. | |
| Modificada | Alta (8.8) | 3.2% | — | Invt Vt-designer | 30/11/2018 | 17/6/2026 | VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution. | |
| Modificada | Alta (8.8) | 2.9% | — | Invt Vt-designer | 30/11/2018 | 17/6/2026 | VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution. | |
| Modificada | Alta (7.8) | 0.42% | — | M2soft Report Designer | 1/11/2018 | 17/6/2026 | M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file. | |
| Modificada | Media (6.1) | 0.77% | — | Avaya Aura Orchestration Designer | 21/9/2018 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1. | |
| Modificada | Alta (8.8) | 0.39% | — | Avaya Orchestration Designer | 21/9/2018 | 17/6/2026 | A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1. | |
| Modificada | Alta (7.8) | 1.4% | — | Siemens TD Keypad Designer | 12/9/2018 | 17/6/2026 | A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory… | |
| Modificada | Media (5.4) | 0.66% | — | Freelancewebdesignerchennai JOB Portal | 18/7/2018 | 17/6/2026 | PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar. | |
| Modificada | Alta (7.8) | 2.0% | — | Advantech Webaccess HMI Designer | 25/4/2018 | 17/6/2026 | Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution. | |
| Modificada | Alta (7.8) | 2.0% | — | Advantech Webaccess HMI Designer | 25/4/2018 | 17/6/2026 | Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution. | |
| Modificada | Alta (7.8) | 2.2% | — | Advantech Webaccess HMI Designer | 25/4/2018 | 17/6/2026 | Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution. | |
| Modificada | Crítica (9.8) | 3.5% | — | Mitsubishielectric E-designer | 17/4/2018 | 17/6/2026 | Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash. | |
| Modificada | Crítica (9.8) | 3.5% | — | Mitsubishielectric E-designer | 17/4/2018 | 17/6/2026 | Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash. | |
| Modificada | Crítica (9.8) | 3.5% | — | Mitsubishielectric E-designer | 17/4/2018 | 17/6/2026 | Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to overwrite arbitrary memory locations. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash. | |
| Modificada | Alta (7.5) | 2.0% | — | Fatek Automation FV DesignerFatek Automation PM Designer | 13/2/2017 | 17/6/2026 | An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. By sending additional valid packets, an attacker could trigger a stack-based buffer overflow and cause a crash. Also, a malicious attacker can trigger a remote buffer overflow on the Fatek… | |
| Modificada | Alta (8.8) | 2.3% | — | Fatek Automation FV DesignerFatek Automation PM Designer | 13/2/2017 | 17/6/2026 | An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. Sending additional valid packets could allow the attacker to cause a crash or to execute arbitrary code, because of Improper Restriction of Operations within the Bounds of a Memory Buffer. | |
| Modificada | Alta (7.8) | 20% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Powerpoint+3 | 14/9/2016 | 17/6/2026 | Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a… | |
| Modificada | Alta (7.8) | 18% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+2 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office… | |
| Modificada | Alta (7.8) | 21% | — | Microsoft ExcelMicrosoft Office Compatibility PackMicrosoft Sharepoint DesignerMicrosoft Sharepoint Foundation | 12/4/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | |
| Modificada | Alta (7.8) | 16% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+4 | 10/2/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and… |