Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 16% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack+1 | 14/7/2015 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Office for Mac 2011, Excel Viewer 2007 SP3, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to… | |
| Modificada | Alta (7.5) | 2.9% | — | Redhat Jbpm-designer | 20/2/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file. | |
| Modificada | Alta (9.3) | 2.1% | — | Threediffy Threedify Designer | 1/1/2015 | 16/6/2026 | The cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allows remote attackers to write to arbitrary files via a pathname in the argument. | |
| Modificada | Alta (9.3) | 3.8% | — | Threedify Designer | 1/1/2015 | 16/6/2026 | Multiple buffer overflows in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allow remote attackers to execute arbitrary code via a long argument to the (1) cmdExport, (2) cmdImport, (3) cmdOpen, or (4) cmdSave method. | |
| Modificada | Media (5.4) | 0.27% | — | Vbwebdesigner Brevir Harian V2 | 19/10/2014 | 17/6/2026 | The Brevir Harian V2 (aka com.brevir.harian.v) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 3.4% | — | Attachmate Verastream Process Designer | 24/7/2014 | 17/6/2026 | Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file. | |
| Modificada | Media (5) | 3.7% | — | Reportico PHP Report Designer | 16/7/2014 | 17/6/2026 | Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter. | |
| Modificada | Alta (9) | 14% | — | Microsoft Office WEB Apps ServerMicrosoft Project ServerMicrosoft Sharepoint DesignerMicrosoft Sharepoint Foundation+4 | 14/5/2014 | 17/6/2026 | Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Project Server 2010 SP1 and SP2 and 2013 Gold and SP1; Web Applications 2010 SP1 and SP2; Office Web Apps Server 2013 Gold and SP1;… | |
| Modificada | Media (6.9) | 0.34% | — | Beijerelectronics Beijer ADPBeijerelectronics H-designer | 28/1/2013 | 16/6/2026 | Buffer overflow in Beijer ADP 6.5.0-180_R1967 and 6.5.1-186_R2942, and H-Designer 6.5.0 B180_R1967, allows local users to gain privileges by inserting a long string into a DLL file. | |
| Modificada | Media (6.9) | 0.97% | — | Adobe Livecycle Designer | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Adobe LiveCycle Designer 8.2.1.3144.1.471865 allows local users to gain privileges via a Trojan horse .dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.82% | — | Adobe Livecycle Designer ES2 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Adobe LiveCycle Designer ES2 9.0.0.20091029.1.612548 allows local users to gain privileges via a Trojan horse objectassisten_US.dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Preprojects Business Cards Designer | 31/8/2012 | 16/6/2026 | SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 29% | 💥 Exploit | Lattice Semiconductor Pac-designer | 21/5/2012 | 16/6/2026 | Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Lovedesigner Lito Lite CMS | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Pdesigner Z-breaknews | 27/8/2008 | 16/6/2026 | SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.5) | 1.2% | — | Drupal Outline Designer Module | 9/7/2008 | 16/6/2026 | The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attackers to gain privileges. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+13 | 7/7/2008 | 16/6/2026 | Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times… | |
| Modificada | Media (4.3) | 1.0% | — | Magnolia Site Designer | 25/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (9.3) | 7.4% | — | Adobe Form ClientAdobe Form Designer | 12/3/2008 | 16/6/2026 | Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls. | |
| Modificada | Media (6.8) | 12% | 💥 Exploit | Microsoft Visual Database Tools Database DesignerMicrosoft Visual Studio | 8/8/2007 | 16/6/2026 | Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method. NOTE: this may overlap CVE-2007-2885 or CVE-2005-2127. | |
| Modificada | Media (4.3) | 9.4% | — | Microsoft Visual Database Tools Database Designer | 30/5/2007 | 16/6/2026 | The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | PHP DB Designer | 23/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php. | |
| Modificada | Media (5) | 1.6% | — | Remlab WEB Mech Designer | 27/11/2006 | 16/6/2026 | REMLAB Web Mech Designer 2.0.5 allows remote attackers to obtain the full path of the script via an incorrect Tonnage parameter to calculate.php that triggers a divide-by-zero error, which leaks the path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Comdev Form Designer | 20/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party… |