Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.44% | — | Opendesign Drawings SDK | 10/4/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdesigner Project Cdesigner | 7/4/2023 | 17/6/2026 | Se ha descubierto que Prestashop cdesigner v3.1.3 a v3.1.8 contiene una vulnerabilidad de inyección de código en el componente CdesignerSaverotateModuleFrontController::initContent(). | |
| Modificada | Media (5.4) | 0.38% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Alta (7.5) | 0.84% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. | |
| Modificada | Alta (7.5) | 0.90% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the… | |
| Modificada | Alta (8.1) | 0.91% | — | React-native-onesignal | 27/3/2023 | 17/6/2026 | OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on… | |
| Modificada | Media (5.5) | 0.23% | 💥 PoC | Stimulsoft Designer | 27/3/2023 | 9/7/2026 | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems. | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Stimulsoft DesignerStimulsoft Viewer | 27/3/2023 | 9/7/2026 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 22/3/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 22/3/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is… | |
| Modificada | Media (6.1) | 0.56% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to… | |
| Modificada | Media (6.1) | 0.59% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. Affected is an unknown function of the file verification.php. The manipulation of the argument txtvaccinationID leads to cross site scripting. It is possible to… | |
| Modificada | Alta (8.1) | 0.86% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The… | |
| Modificada | Alta (8.8) | 1.1% | — | Upthemes Designfolio-plus | 7/3/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.53% | — | Smg-webdesign Shortcode FOR Font Awesome | 21/2/2023 | 17/6/2026 | The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.5) | 0.34% | — | Adobe Indesign | 17/2/2023 | 17/6/2026 | Adobe InDesign versions ID18.1 (and earlier) and ID17.4 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user… | |
| Modificada | Alta (8.8) | 0.26% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Media (5.5) | 0.25% | — | Pesign Project PesignFedoraproject FedoraRedhat Enterprise Linux | 2/2/2023 | 17/6/2026 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This… | |
| Modificada | Media (5.4) | 0.63% | — | Solwininfotech Blog Designer | 30/1/2023 | 17/6/2026 | El complemento Blog Designer de WordPress anterior a 2.4.1 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado. | |
| Modificada | Media (5.4) | 0.44% | — | Infornweb News & Blog Designer Pack | 30/1/2023 | 17/6/2026 | El complemento News & Blog Designer Pack de WordPress anterior a 3.3 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado. | |
| Analizada | Media (5.4) | 0.47% | — | Infornweb Posts List Designer | 30/1/2023 | 17/6/2026 | El complemento Posts List Designer by Category de WordPress anterior a 3.2 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían ser… |