Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Special Minds Design AND Software E-commerceAI | 22/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection. This issue affects e-Commerce: before 22.11.2024. | |
| Analizada | Media (5.5) | 0.29% | — | Adobe Indesign | 21/11/2024 | 17/6/2026 | InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Aplazada | Media (6.4) | 0.53% | — | Prestalife Product DesignerAI | 21/11/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.39% | — | Intelligentdesign Keymaster Chord Notation FreeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligentDesign Keymaster Chord Notation Free keymaster-chord-notation-free allows Stored XSS.This issue affects Keymaster Chord Notation Free: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.4) | 0.48% | — | Harmonicdesign HD Quiz Save Results LightAI | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through <= 0.5. | |
| Analizada | Media (5.3) | 0.55% | — | Avovkdesign Hide Links | 13/11/2024 | 17/6/2026 | The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. | |
| Analizada | Media (5.5) | 0.29% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… | |
| Analizada | Media (5.5) | 0.29% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… | |
| Analizada | Media (5.5) | 0.29% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… | |
| Analizada | Alta (7.8) | 0.45% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.48% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.48% | — | Adobe Indesign | 12/11/2024 | 17/6/2026 | InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (6.5) | 0.42% | — | Andsonsdesign Wp-contest | 11/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sophia M Williams WP Contest wp-contest allows SQL Injection.This issue affects WP Contest: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Designerken Reftagger ShortcodeAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designerken Reftagger Shortcode reftagger-shortcode allows Stored XSS.This issue affects Reftagger Shortcode: from n/a through <= 1.1. | |
| Analizada | Alta (8.8) | 0.46% | — | Etoilewebdesign Order Tracking | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12. | |
| Aplazada | Media (5.3) | 0.36% | — | Fetchdesigns Sign-up SheetsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12. | |
| Aplazada | Alta (7.5) | 0.48% | — | Pickplugins Product DesignerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33. | |
| Aplazada | Alta (8.8) | 0.44% | — | Hercules Design Hercules CoreAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hercules Core: from n/a through 6.5. | |
| Aplazada | Alta (8.6) | 1.4% | 💥 PoC | Chetan Khandla WOO Product DesignAI | 30/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.5) | 1.1% | 💥 PoC | Chetan Khandla Woocommerce Product DesignAI | 30/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0. | |
| Modificada | Media (6.1) | 0.31% | — | Coralwebdesign CWD 3D Image Gallery | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D Image Gallery cwd-3d-image-gallery allows Reflection Injection.This issue affects CWD 3D Image Gallery: from n/a through <= 1.0. | |
| Aplazada | Crítica (10) | 1.1% | 💥 PoC | Chetan Khandla Woocommerce Product DesignAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Indesign | 9/10/2024 | 17/6/2026 | InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed, could run arbitrary code in the context of… | |
| Aplazada | Crítica (9.2) | 0.39% | — | RSM Design Website TemplateAI | 27/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection. This issue affects Website Template: before 1.2. |