Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.40% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mastergo-design Mastergo-magic-mcpAI | 14/7/2026 | 15/7/2026 | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function execute of the file src/tools/get-c2d.ts of the component mcp__C2d. Performing a manipulation of the argument filePath results in path traversal. The attack requires a local approach. The exploit has… | |
| Analizada | Alta (7.3) | 0.17% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to… | |
| Analizada | Alta (7.3) | 0.15% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a… | |
| Analizada | Media (5.4) | 0.18% | — | Rockwellautomation Studio 5000 Logix Designer | 14/7/2026 | 25/8/2026 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+6 | 14/7/2026 | 5/10/2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter… | |
| Aplazada | Media (6.1) | 0.25% | — | Webbeyaz WEB Design Medikum WEBAI | 8/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Webbeyaz WEB Design Medikum WEBAI | 8/7/2026 | 9/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Crítica (9.1) | 1.2% | — | Printcart WEB TO Print Product DesignerAI | 3/7/2026 | 7/7/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key'… | |
| Aplazada | Alta (7.5) | 0.56% | — | Emarketdesign Request A QuoteAI | 2/7/2026 | 2/7/2026 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the… | |
| Aplazada | Media (6.5) | 0.22% | — | Woocommerce Designer PROAI | 29/6/2026 | 1/7/2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. | |
| Aplazada | Media (4.3) | 0.26% | — | Harmonicdesign HD QuizAI | 27/6/2026 | 29/6/2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and… | |
| Aplazada | Media (5.4) | 0.29% | — | Designsandcode Forget About Shortcode ButtonsAI | 26/6/2026 | 5/10/2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. | |
| Aplazada | Media (5.3) | 0.39% | — | Printcart WEB TO Print Product DesignerAI | 26/6/2026 | 6/10/2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server. | |
| Aplazada | Media (5.4) | 0.18% | — | Pencidesign SoledadAI | 11/6/2026 | 29/9/2026 | Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Soledad: from n/a through 8.2.5. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.26% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Media (5.5) | 0.23% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user… | |
| Analizada | Media (5.5) | 0.23% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user… | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |