Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.19% | — | Solidworks EdrawingsAISolidworks DesktopAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file. | |
| Aplazada | Alta (7.8) | 0.18% | — | 3DS Solidworks EdrawingsAI | 15/7/2025 | 17/6/2026 | Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file. | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Aplazada | Alta (7.5) | 0.34% | — | Wpswings Membership FOR WoocommerceAI | 9/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.8.1. | |
| Analizada | Media (4.9) | 0.38% | — | Wpswings Ultimate Gift Cards FOR Woocommerce | 3/6/2025 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.8) | 0.22% | — | Solidworks EdrawingsAISolidworks DesktopAI | 2/5/2025 | 17/6/2026 | Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file. | |
| Aplazada | Alta (7.8) | 0.21% | — | 3DS Solidworks EdrawingsAI3DS Solidworks DesktopAI | 2/5/2025 | 17/6/2026 | Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted OBJÂ file. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpswings Wallet System FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Reflected XSS.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.8. | |
| Aplazada | Media (6.5) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows DOM-Based XSS.This issue affects Membership For WooCommerce: from n/a through <= 2.8.0. | |
| Analizada | Media (4.3) | 0.25% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance,… | |
| Analizada | Media (4.3) | 0.15% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it… | |
| Modificada | Crítica (9.8) | 4.1% | 💥 Exploit | Wpswings Woocommerce Ultimate Gift Card | 28/2/2025 | 17/6/2026 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (5.4) | 0.31% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 via several functions due to missing validation on a user controlled key. This… | |
| Analizada | Alta (7.5) | 0.47% | — | Wpswings Return Refund AND Exchange FOR Woocommerce | 14/2/2025 | 17/6/2026 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.78% | 💥 PoC | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 8/1/2025 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpswings ONE Click Upsell Funnel FOR WoocommerceAI | 21/12/2024 | 17/6/2026 | The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wps_wocuf_pro_yes shortcode in… | |
| Aplazada | Alta (8.1) | 0.19% | — | Opendesign Drawings SDKAI | 4/12/2024 | 17/6/2026 | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpswings Woocommerce Ultimate Gift CardAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Reflected XSS.This issue affects WooCommerce Ultimate Gift Card: from n/a through < 2.9.1. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpswings Wallet System FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13. | |
| Analizada | Media (6.4) | 0.39% | — | Pterodactyl Wings | 3/5/2024 | 17/6/2026 | Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. This would allow… | |
| Analizada | Alta (8.4) | 0.54% | — | Pterodactyl Wings | 3/5/2024 | 17/6/2026 | Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in… | |
| Aplazada | Media (5.4) | 0.21% | — | Wpswings Wallet System FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9. | |
| Aplazada | Media (5.4) | 0.39% | — | Wpswings Points AND Rewards FOR WoocommerceAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0. | |
| Aplazada | Alta (7.8) | 0.36% | — | Solidworks EdrawingsAI | 4/4/2024 | 17/6/2026 | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT… |