Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.1%—Advantech Webaccess HMI Designer2/8/201917/6/2026
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
ModificadaAlta (7.5)2.0%—Fatek Automation FV DesignerFatek Automation PM Designer V321/3/201917/6/2026
A malicious attacker can trigger a remote buffer overflow in the Communication Server in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0.
ModificadaAlta (7.5)1.7%—SAP Financial Consolidation Cube DesignerSAP Financial Consolidation Cube Designer Bobj Eades8/1/201917/6/2026
A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the password hash of an admin user.
ModificadaCrítica (10)1.8%—Obeo UML Designer20/12/201817/6/2026
UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.
ModificadaAlta (8.8)3.2%—Invt Vt-designer30/11/201817/6/2026
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to known memory locations. This may cause the program to crash or allow remote code execution.
ModificadaAlta (8.8)2.9%—Invt Vt-designer30/11/201817/6/2026
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution.
ModificadaAlta (7.8)0.42%—M2soft Report Designer1/11/201817/6/2026
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
ModificadaMedia (6.1)0.77%—Avaya Aura Orchestration Designer21/9/201817/6/2026
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
ModificadaAlta (8.8)0.39%—Avaya Orchestration Designer21/9/201817/6/2026
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
ModificadaAlta (7.8)1.4%—Siemens TD Keypad Designer12/9/201817/6/2026
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory…
ModificadaMedia (5.4)0.66%—Freelancewebdesignerchennai JOB Portal18/7/201817/6/2026
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
ModificadaAlta (7.8)2.0%—Advantech Webaccess HMI Designer25/4/201817/6/2026
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
ModificadaAlta (7.8)2.0%—Advantech Webaccess HMI Designer25/4/201817/6/2026
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
ModificadaAlta (7.8)2.2%—Advantech Webaccess HMI Designer25/4/201817/6/2026
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
ModificadaCrítica (9.8)3.5%—Mitsubishielectric E-designer17/4/201817/6/2026
Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.
ModificadaCrítica (9.8)3.5%—Mitsubishielectric E-designer17/4/201817/6/2026
Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.
ModificadaCrítica (9.8)3.5%—Mitsubishielectric E-designer17/4/201817/6/2026
Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to overwrite arbitrary memory locations. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.
ModificadaAlta (7.5)2.0%—Fatek Automation FV DesignerFatek Automation PM Designer13/2/201717/6/2026
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. By sending additional valid packets, an attacker could trigger a stack-based buffer overflow and cause a crash. Also, a malicious attacker can trigger a remote buffer overflow on the Fatek…
ModificadaAlta (8.8)2.3%—Fatek Automation FV DesignerFatek Automation PM Designer13/2/201717/6/2026
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. Sending additional valid packets could allow the attacker to cause a crash or to execute arbitrary code, because of Improper Restriction of Operations within the Bounds of a Memory Buffer.
ModificadaAlta (7.8)20%—Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+114/9/201617/6/2026
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow…
ModificadaAlta (7.8)17%—Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+114/9/201617/6/2026
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow…
ModificadaAlta (7.8)17%—Microsoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Powerpoint+314/9/201617/6/2026
Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a…
ModificadaAlta (7.8)18%—Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+214/9/201617/6/2026
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office…
ModificadaAlta (7.8)21%—Microsoft ExcelMicrosoft Office Compatibility PackMicrosoft Sharepoint DesignerMicrosoft Sharepoint Foundation12/4/201617/6/2026
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
ModificadaAlta (7.8)16%—Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+410/2/201617/6/2026
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and…
Orbitaley — Vulnerabilidades