Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 10/6/2025 | 17/6/2026 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Crítica (9.3) | 1.4% | 💥 Exploit | Mystyleplatform Mystyle-custom-product-designerAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform MyStyle Custom Product Designer mystyle-custom-product-designer allows Blind SQL Injection.This issue affects MyStyle Custom Product Designer: from n/a through <= 3.21.1. | |
| Aplazada | Media (5.5) | 0.30% | — | Esigngenie Foxit Esign FOR WordpressAI | 6/6/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for WordPress esign-genie-for-wp allows Retrieve Embedded Sensitive Data.This issue affects Foxit eSign for WordPress: from n/a through <= 2.0.3. | |
| Aplazada | Media (5.9) | 0.26% | — | Marchettidesign Next Event CalendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2. | |
| Analizada | Media (6.4) | 0.22% | — | Emarketdesign WP Easy Contact | 4/6/2025 | 17/6/2026 | The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (4.8) | 0.15% | — | Blackmagicdesign Davinci ResolveAI | 29/5/2025 | 17/6/2026 | Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints allows to substitute a legitimate dylib with malicious one. A local attacker with unprivileged access can execute the application with altered dynamic library successfully bypassing Transparency,… | |
| Aplazada | Crítica (10) | 0.42% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Finance ConsultantAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes PET WorldAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Crafts AND ArtsAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5. | |
| Modificada | Media (6.1) | 0.28% | — | Jocoxdesign Tiger | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0. | |
| Analizada | Media (4.8) | 0.31% | — | Harmonicdesign HD Quiz | 15/5/2025 | 17/6/2026 | The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 0.29% | — | Etoilewebdesign Front END Users | 15/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35. | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially… | |
| Aplazada | Baja (2) | 0.33% | — | EsignaviewerAI | 15/5/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. | |
| Analizada | Media (5.5) | 0.25% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in… | |
| Analizada | Media (5.5) | 0.25% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction… | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.16% | — | Google WEB Designer | 12/5/2025 | 17/6/2026 | Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature | |
| Modificada | Crítica (9.8) | 0.30% | — | Wbcomdesigns Activity Link Preview FOR Buddypress | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request Forgery.This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through <= 1.4.4. |