Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.56% | — | ExcalidrawAI | 17/4/2024 | 17/6/2026 | excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without… | |
| Aplazada | Alta (7.8) | 0.36% | — | Solidworks EdrawingsAI | 4/4/2024 | 17/6/2026 | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT… | |
| Aplazada | Alta (7.8) | 0.32% | — | Solidworks EdrawingsAI | 4/4/2024 | 17/6/2026 | Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT… | |
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Opendesign Drawings SDK | 26/12/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Media (5.4) | 0.38% | — | Assortedchips Drawit | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in assorted[chips] DrawIt (draw.Io) plugin <= 1.1.3 versions. | |
| Modificada | Alta (7.8) | 0.27% | — | Opendesign Drawings SDK | 7/11/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code… | |
| Modificada | Media (6.1) | 0.56% | — | Excalidraw | 16/8/2023 | 17/6/2026 | Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization. | |
| Modificada | Crítica (9.8) | 2.3% | — | Diagrams Drawio | 27/7/2023 | 17/6/2026 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. | |
| Modificada | Crítica (9.8) | 1.2% | — | Diagrams Drawio | 27/7/2023 | 17/6/2026 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. | |
| Modificada | Media (6.1) | 0.40% | — | Diagrams Drawio | 27/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3. | |
| Modificada | Alta (7.5) | 0.97% | — | Diagrams Drawio | 26/6/2023 | 17/6/2026 | Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. | |
| Modificada | Media (4.3) | 0.50% | — | Nsqua Draw Attention | 9/6/2023 | 17/6/2026 | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the… | |
| Modificada | Media (6.1) | 0.53% | — | Diagrams Drawio | 1/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. | |
| Modificada | Alta (7.8) | 0.22% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length… | |
| Modificada | Alta (7.8) | 0.32% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.44% | — | Opendesign Drawings SDK | 10/4/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.45% | — | Wondershare Edraw-max | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file. | |
| Modificada | Alta (7.8) | 0.39% | — | Wondershare Edrawmind | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co, Ltd Edrawmind v.10.0.6 allows a remote attacker to executea arbitrary commands via the WindowsCodescs.dll file. | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.93% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… |