Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.20% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Analizada | Media (5.3) | 0.19% | — | Altium Designer | 22/1/2026 | 17/6/2026 | Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data. | |
| Analizada | Media (5.3) | 0.25% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (6.5) | 0.29% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (6.5) | 0.26% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Aplazada | Media (5.3) | 0.32% | — | Radykal Fancy Product DesignerAI | 16/1/2026 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 1.5% | 💥 PoC | News AND Blog Designer BundleAI | 14/1/2026 | 17/6/2026 | The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in… | |
| Analizada | Media (5.5) | 0.18% | — | Adobe Substance 3D Designer | 13/1/2026 | 28/8/2026 | Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Alta (7.8) | 0.18% | — | Adobe Substance 3D Designer | 13/1/2026 | 28/8/2026 | Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Aplazada | Media (5.1) | 0.09% | — | Mitsubishielectric GT Designer3 Version1 Got2000AIMitsubishielectric GT Designer3 Version1 Got1000AI | 17/12/2025 | 17/6/2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to obtain plaintext credentials from the project file for GT Designer3. This could… | |
| Aplazada | Media (6.5) | 0.18% | — | Radykal Fancy Product DesignerAI | 16/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX action. The plugin validates the URL by calling… | |
| Aplazada | Media (5.9) | 0.31% | — | Radykal Fancy Product DesignerAI | 16/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the 'fpd_custom_uplod_file' AJAX action, which flows directly into the… | |
| Aplazada | Alta (7.2) | 0.25% | — | Radykal Fancy Product DesignerAI | 12/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.30% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 2/12/2025 | 17/6/2026 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.1) | 0.50% | — | Designervily GreenifyAI | 6/11/2025 | 5/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Greenify greenify allows PHP Local File Inclusion.This issue affects Greenify: from n/a through <= 2.2. | |
| Aplazada | Alta (8.6) | 1.9% | 💥 Exploit | Woocommerce Designer PROAI | 31/10/2025 | 17/6/2026 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read. | |
| Aplazada | Media (5.3) | 0.27% | — | Solwin Blog Designer PROAI | 29/10/2025 | 5/10/2026 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8. | |
| Aplazada | Crítica (9.8) | 33% | 💥 PoC | Woocommerce Designer PROAI | 24/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily XcareAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.This issue affects Xcare: from n/a through < 6.5. | |
| Aplazada | Alta (8.1) | 0.52% | — | Designervily KarzoAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allows PHP Local File Inclusion.This issue affects Karzo: from n/a through < 2.6. | |
| Aplazada | Alta (8.7) | 0.37% | — | Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI | 14/10/2025 | 17/6/2026 | A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Woocommerce Designer PROAI | 11/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it… | |
| Aplazada | Crítica (10) | 0.39% | — | Harutheme Woocommerce Designer PROAI | 26/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects WooCommerce Designer Pro: from n/a through <= 1.9.24. |