Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Analizada | Alta (7.8) | 0.21% | — | 3DS Solidworks Edrawings | 16/2/2026 | 17/6/2026 | A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7.8) | 0.29% | — | Solidworks EdrawingsAI | 26/1/2026 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | |
| Aplazada | Alta (7) | 0.15% | — | Opendesign Drawings SDKAI | 22/12/2025 | 17/6/2026 | A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation units (Static… | |
| Aplazada | Media (4.3) | 0.14% | — | Lucky Draw ContestsAI | 13/12/2025 | 17/6/2026 | The Lucky Draw Contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation in misc-settings.php. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they… | |
| Aplazada | Alta (8.8) | 0.45% | — | Drawing-captcha APPAI | 16/10/2025 | 17/6/2026 | Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links. These links can… | |
| Aplazada | Alta (7.8) | 0.17% | — | 3DS Solidworks EdrawingsAI | 17/9/2025 | 25/9/2026 | A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.17% | — | 3DS Solidworks EdrawingsAI | 17/9/2025 | 25/9/2026 | A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file. | |
| Aplazada | Alta (7.8) | 0.17% | — | Solidworks EdrawingsAISolidworks DesktopAI | 17/9/2025 | 25/9/2026 | An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file. | |
| Aplazada | Media (5.3) | 0.46% | — | DrawnixAI | 15/9/2025 | 17/6/2026 | drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vulnerability exists in the debug logging functionality. User controlled content is inserted directly into the DOM via innerHTML without sanitization when the global function __drawnix__web__console is… | |
| Aplazada | Alta (7.8) | 0.18% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted IPT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Alta (7.8) | 0.22% | — | Solidworks EdrawingsAISolidworks DesktopAI | 2/5/2025 | 17/6/2026 | Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file. | |
| Aplazada | Alta (7.8) | 0.21% | — | 3DS Solidworks EdrawingsAI3DS Solidworks DesktopAI | 2/5/2025 | 17/6/2026 | Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted OBJÂ file. | |
| Analizada | Crítica (9.8) | 0.91% | — | Infodraw Pmrs-102 Firmware | 20/4/2025 | 17/6/2026 | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing. | |
| Aplazada | Crítica (9.1) | 0.72% | 💥 PoC | Aidraw I DrawAI | 17/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0. | |
| Aplazada | Media (5.4) | 0.28% | — | Nsquared Draw AttentionAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15. | |
| Aplazada | Media (5.4) | 0.37% | — | Appsbd Mini Cart Drawer FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0. | |
| Aplazada | Alta (8.1) | 0.19% | — | Opendesign Drawings SDKAI | 4/12/2024 | 17/6/2026 | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack… | |
| Modificada | Baja (3.3) | 0.67% | — | Wondershare Edraw | 2/10/2024 | 17/6/2026 | A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and… |