Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.39% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.39% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.39% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.39% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.42% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit… | |
| Analizada | Alta (7.8) | 0.40% | — | Fatek Fvdesigner | 3/5/2024 | 17/6/2026 | Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Media (6.3) | 0.46% | — | Radykal Fancy Product Designer | 26/4/2024 | 17/6/2026 | The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users | |
| Aplazada | Alta (7.1) | 0.35% | — | Andondesign UdesignAI | 25/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign allows Reflected XSS.This issue affects UDesign: from n/a through 4.7.3. | |
| Modificada | Media (6.1) | 0.37% | — | Designinvento Directorypress | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress allows Reflected XSS.This issue affects DirectoryPress: from n/a through 3.6.7. | |
| Aplazada | Media (5.9) | 0.34% | — | Daniele DE Rosa Backend DesignerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniele De Rosa Backend Designer allows Stored XSS.This issue affects Backend Designer: from n/a through 1.3. | |
| Aplazada | Alta (7.1) | 0.33% | — | Canva - Design Beautiful Blog GraphicsAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Canva Canva – Design beautiful blog graphics allows Reflected XSS.This issue affects Canva – Design beautiful blog graphics: from n/a through 1.2.4. | |
| Aplazada | Media (4.3) | 0.20% | — | Etoilewebdesign Ultimate Product CatalogueAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15. | |
| Analizada | Media (4.8) | 0.44% | — | Radykal Fancy Product Designer | 15/4/2024 | 17/6/2026 | The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (4.3) | 0.20% | — | Fetchdesigns Sign-up SheetsAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1. | |
| Analizada | Media (5.5) | 0.34% | — | Adobe Indesign | 10/4/2024 | 17/6/2026 | InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Media (5.4) | 0.22% | — | Pencidesign Soledad | 9/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. | |
| Modificada | Media (6.5) | 0.44% | — | Pencidesign Soledad | 9/4/2024 | 17/6/2026 | Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. | |
| Modificada | Alta (7.1) | 0.43% | — | Pencidesign Soledad | 9/4/2024 | 17/6/2026 | Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. | |
| Aplazada | Alta (8.7) | 0.47% | — | Pickplugins Product DesignerAI | 7/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32. | |
| Aplazada | Alta (7.1) | 0.35% | — | Pulsar WEB Design Weekly Class ScheduleAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class Schedule: from n/a through 3.19. | |
| Aplazada | Crítica (9.9) | 0.70% | — | Hercules Design Hercules CoreAI | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4. | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Front END Users | 26/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25. | |
| Analizada | Media (6.5) | 0.64% | — | Radykal Fancy Product Designer | 18/3/2024 | 17/6/2026 | The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators. | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Ultimate Reviews | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from n/a through 3.2.8. | |
| Analizada | Alta (8.1) | 0.31% | — | Prestalife Product Designer | 3/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in the postProcess() method. |