Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Single PropertyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Knowledge BaseAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes KriyaAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4. | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily XcareAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.This issue affects Xcare: from n/a through < 6.5. | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily KarzoAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allows PHP Local File Inclusion.This issue affects Karzo: from n/a through < 2.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Designthemes TrissAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Triss triss allows Reflected XSS.This issue affects Triss: from n/a through <= 2.6. | |
| Aplazada | Media (6.3) | 0.24% | — | Andondesign U-design-coreAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UDesign Core: from n/a through <= 4.14.0. | |
| Aplazada | Alta (8.8) | 0.61% | — | Designthemes Solar EnergyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <= 3.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Andondesign U-design-coreAI | 22/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign Core u-design-core allows Reflected XSS.This issue affects UDesign Core: from n/a through <= 4.14.0. | |
| Aplazada | Media (6.4) | 0.19% | — | Material Design Iconic Font IntegrationAI | 22/10/2025 | 17/6/2026 | The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdiconic' shortcode in all versions up to, and including, 2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.1) | 0.39% | 💥 PoC | Ascertia Signinghub | 20/10/2025 | 5/7/2026 | A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack. | |
| Modificada | Alta (7.5) | 0.46% | 💥 PoC | Ascertia Signinghub | 20/10/2025 | 5/7/2026 | A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files. | |
| Modificada | Alta (7.1) | 0.32% | 💥 PoC | Ascertia Signinghub | 20/10/2025 | 5/7/2026 | Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created. | |
| Analizada | Crítica (9.8) | 0.60% | 💥 PoC | Ascertia Signinghub | 17/10/2025 | 17/6/2026 | A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack. | |
| Modificada | Crítica (9.8) | 0.63% | 💥 PoC | Ascertia Signinghub | 17/10/2025 | 5/7/2026 | An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file. | |
| Aplazada | Alta (8.7) | 0.37% | — | Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI | 14/10/2025 | 17/6/2026 | A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Woocommerce Designer PROAI | 11/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it… | |
| Aplazada | Crítica (9.8) | 0.60% | 💥 PoC | Oauth Single Sign ON SSOAI | 4/10/2025 | 17/6/2026 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 6.26.12. This is due to the plugin performing unsafe JWT token processing without verification or validation in the `get_resource_owner_from_id_token`… | |
| Aplazada | Media (4.3) | 0.21% | — | WdesignkitAI | 4/10/2025 | 17/6/2026 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is… | |
| Aplazada | Media (5.5) | 0.22% | — | Ultimate Multi Design Video CarouselAI | 3/10/2025 | 17/6/2026 | The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts… | |
| Analizada | Alta (8.8) | 0.56% | — | Digisigner ONE | 1/10/2025 | 17/6/2026 | DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. | |
| Analizada | Alta (8.5) | 0.18% | — | NI Circuit Design Suite | 30/9/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Analizada | Alta (8.5) | 0.18% | — | NI Circuit Design Suite | 30/9/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Aplazada | Media (6.1) | 0.20% | — | Webbeyaz Website Design Website SoftwareAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz Website Design Website Software allows Cross-Site Scripting (XSS). This issue affects Website Software: through 2025.07.14. | |
| Aplazada | Crítica (10) | 0.39% | — | Harutheme Woocommerce Designer PROAI | 26/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects WooCommerce Designer Pro: from n/a through <= 1.9.24. |