Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

186 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.56%—ExcalidrawAI17/4/202417/6/2026
excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without…
AplazadaAlta (7.8)0.36%—Solidworks EdrawingsAI4/4/202417/6/2026
Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT…
AplazadaAlta (7.8)0.32%—Solidworks EdrawingsAI4/4/202417/6/2026
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT…
ModificadaAlta (7.8)0.19%💥 PoCOpendesign Drawings SDK26/12/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaMedia (5.4)0.38%—Assortedchips Drawit22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in assorted[chips] DrawIt (draw.Io) plugin <= 1.1.3 versions.
ModificadaAlta (7.8)0.27%—Opendesign Drawings SDK7/11/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code…
ModificadaMedia (6.1)0.56%—Excalidraw16/8/202317/6/2026
Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
ModificadaCrítica (9.8)2.3%—Diagrams Drawio27/7/202317/6/2026
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
ModificadaCrítica (9.8)1.2%—Diagrams Drawio27/7/202317/6/2026
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.
ModificadaMedia (6.1)0.40%—Diagrams Drawio27/7/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3.
ModificadaAlta (7.5)0.97%—Diagrams Drawio26/6/202317/6/2026
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
ModificadaMedia (4.3)0.50%—Nsqua Draw Attention9/6/202317/6/2026
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the…
ModificadaMedia (6.1)0.53%—Diagrams Drawio1/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8.
ModificadaAlta (7.8)0.22%—Opendesign Drawings SDK15/4/202317/6/2026
A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length…
ModificadaAlta (7.8)0.32%—Opendesign Drawings SDK15/4/202317/6/2026
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.44%—Opendesign Drawings SDK10/4/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
ModificadaAlta (7.8)0.45%—Wondershare Edraw-max4/4/202317/6/2026
An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.
ModificadaAlta (7.8)0.39%—Wondershare Edrawmind4/4/202317/6/2026
An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file.
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaMedia (5.5)0.83%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)0.87%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.93%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaMedia (5.5)0.83%—Coreldraw29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
Orbitaley — Vulnerabilidades