Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | 💥 PoC | Redpine Signals Rs9116 Wiseconnect SDKAI | 17/11/2025 | 7/10/2026 | In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation | |
| Modificada | Media (6.5) | 0.30% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded… | |
| Modificada | Media (5.3) | 0.25% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with admin access the… | |
| Modificada | Media (5.3) | 0.27% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can be set to any path without any restrictions by an admin user. In the case that the provided path points to an existing file,… | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Indesign | 11/11/2025 | 17/6/2026 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.31% | — | Adobe Indesign | 11/11/2025 | 17/6/2026 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Indesign | 11/11/2025 | 17/6/2026 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Indesign | 11/11/2025 | 17/6/2026 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (6.1) | 0.21% | — | Redhat Single Sign-onAI | 6/11/2025 | 7/10/2026 | A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Fetchdesigns Sign-up SheetsAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Andondesign U-design-coreAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign Core u-design-core.This issue affects UDesign Core: from n/a through <= 4.14.1. | |
| Aplazada | Alta (8.1) | 0.53% | — | Designervily GreenifyAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Greenify greenify allows PHP Local File Inclusion.This issue affects Greenify: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.23% | — | Pencidesign Penci Bookmark & FollowAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Bookmark & Follow penci-bookmark-follow allows Reflected XSS.This issue affects Penci Bookmark & Follow: from n/a through < 2.4. | |
| Analizada | Crítica (9.8) | 1.2% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… | |
| Analizada | Alta (7.2) | 0.96% | 💥 PoC | Xibosignage Xibo | 4/11/2025 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions… | |
| Aplazada | Alta (7.6) | 0.32% | — | Silabs Z-wave PIR Sensor Reference DesignAISilabs SisdkAI | 31/10/2025 | 7/10/2026 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1. | |
| Aplazada | Alta (8.6) | 1.9% | 💥 Exploit | Woocommerce Designer PROAI | 31/10/2025 | 7/10/2026 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read. | |
| Analizada | Media (6.1) | 0.20% | — | Salsa.digital Civictheme Design System | 30/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0. | |
| Analizada | Alta (7.5) | 0.31% | — | Salsa.digital Civictheme Design System | 30/10/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Solwin Blog Designer PROAI | 29/10/2025 | 5/10/2026 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8. | |
| Aplazada | Alta (7.1) | 0.11% | — | Fanbridge SignupAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This issue affects FanBridge signup: from n/a through <= 0.6. | |
| Aplazada | Media (6.5) | 0.17% | — | Designinvento DirectorypressAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25. | |
| Aplazada | Crítica (9.8) | 33% | 💥 PoC | Woocommerce Designer PROAI | 24/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Arksigner Software AND Hardware INC AcbakimzalaAI | 23/10/2025 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows PHP Local File Inclusion. This issue affects AcBakImzala: before v5.1.4. | |
| Aplazada | Media (5.4) | 0.22% | — | Arksigner Software AND Hardware INC AcbakimzalaAI | 23/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows Reflected XSS. This issue affects AcBakImzala: before v5.1.4. |