Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
AplazadaAlta (7.5)0.46%—Lumise Product Designer FOR WoocommerceAI23/7/202623/7/2026
The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before…
AnalizadaAlta (7.3)0.17%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to…
AnalizadaAlta (7.3)0.15%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a…
AnalizadaMedia (5.4)0.18%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the…
AplazadaCrítica (9.1)1.2%—Printcart WEB TO Print Product DesignerAI3/7/20267/7/2026
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key'…
AplazadaMedia (6.5)0.22%—Woocommerce Designer PROAI29/6/20261/7/2026
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
AplazadaMedia (5.3)0.39%—Printcart WEB TO Print Product DesignerAI26/6/20266/10/2026
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server.
ModificadaAlta (7.8)0.26%—Adobe Substance 3D Designer12/5/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.26%—Adobe Substance 3D Designer12/5/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.26%—Adobe Substance 3D Designer12/5/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.26%—Adobe Substance 3D Designer12/5/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaMedia (6.3)0.29%—Adobe Substance 3D Designer12/5/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended…
AplazadaMedia (6.4)0.32%—SP Blog DesignerAI12/5/202617/6/2026
The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
Pendiente de análisisMedia (4.3)0.32%—Wago Smart DesignerAI16/4/202617/6/2026
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
AplazadaCrítica (9.3)0.28%—King-theme Lumise Product DesignerAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9.
AnalizadaAlta (8.4)0.12%—Google WEB Designer27/2/202617/6/2026
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
AnalizadaMedia (5.5)0.16%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaMedia (5.5)0.16%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaMedia (5.5)0.15%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in…
AnalizadaMedia (5.5)0.16%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a…
AnalizadaMedia (5.5)0.15%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in…
AnalizadaAlta (7.8)0.20%—Adobe Substance 3D Designer10/2/202628/8/2026
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Orbitaley — Vulnerabilidades