Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.42% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Finance ConsultantAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes PET WorldAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.57% | — | Designthemes Crafts AND ArtsAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/a through <= 2.5. | |
| Modificada | Media (6.1) | 0.28% | — | Jocoxdesign Tiger | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0. | |
| Analizada | Media (4.8) | 0.31% | — | Harmonicdesign HD Quiz | 15/5/2025 | 17/6/2026 | The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.8) | 0.29% | — | Etoilewebdesign Front END Users | 15/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35. | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted… | |
| Analizada | Alta (8.5) | 0.20% | — | NI Circuit Design Suite | 15/5/2025 | 17/6/2026 | There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially… | |
| Aplazada | Baja (2) | 0.33% | — | EsignaviewerAI | 15/5/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. | |
| Analizada | Alta (7.6) | 0.59% | 💥 Exploit | Humansignal Label Studio | 14/5/2025 | 17/6/2026 | Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The vulnerability… | |
| Analizada | Media (5.5) | 0.25% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in… | |
| Analizada | Media (5.5) | 0.25% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction… | |
| Analizada | Alta (7.8) | 0.27% | — | Adobe Indesign | 13/5/2025 | 17/6/2026 | InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.16% | — | Google WEB Designer | 12/5/2025 | 17/6/2026 | Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature | |
| Aplazada | Alta (8.5) | 0.19% | — | Brightsign OSAI | 7/5/2025 | 17/6/2026 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained. | |
| Modificada | Crítica (9.8) | 0.30% | — | Wbcomdesigns Activity Link Preview FOR Buddypress | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request Forgery.This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through <= 1.4.4. | |
| Aplazada | Alta (8.1) | 0.36% | 💥 PoC | Iqonic Design GraphinaAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affects Graphina: from n/a through <= 3.0.4. | |
| Aplazada | Media (5.4) | 0.33% | — | Iqonic Design GraphinaAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Graphina: from n/a through <= 3.0.4. | |
| Aplazada | Crítica (9.8) | 0.55% | — | OTP Less ONE TAP Sign INAI | 2/5/2025 | 17/6/2026 | The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due to the plugin not properly validating a user's identity prior to updating their details, like email. This makes it possible for unauthenticated attackers to change… | |
| Aplazada | Media (5.3) | 0.33% | — | Vinodvaswani9 Bulk Assign Linked Products FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1. |