Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Media (5.5) | 0.81% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Crítica (9.8) | 0.96% | — | Oretnom23 Raffle Draw System | 6/2/2023 | 17/6/2026 | Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | |
| Modificada | Crítica (9.8) | 0.89% | — | Oretnom23 Raffle Draw System | 6/2/2023 | 17/6/2026 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. | |
| Modificada | Crítica (9.8) | 0.89% | — | Oretnom23 Raffle Draw System | 6/2/2023 | 17/6/2026 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | |
| Modificada | Crítica (9.8) | 0.89% | — | Oretnom23 Raffle Draw System | 6/2/2023 | 17/6/2026 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | |
| Modificada | Crítica (9.8) | 0.87% | — | Oretnom23 Raffle Draw System | 6/2/2023 | 17/6/2026 | Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | |
| Modificada | Media (6.1) | 0.67% | — | Diagrams Drawio | 7/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2. | |
| Modificada | Media (6.1) | 0.80% | — | Diagrams Drawio | 16/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. | |
| Modificada | Alta (7.8) | 1.2% | — | Diagrams Drawio | 9/9/2022 | 17/6/2026 | OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. | |
| Modificada | Media (6.1) | 0.66% | — | Diagrams Drawio | 8/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | |
| Modificada | Media (6.1) | 0.66% | — | Diagrams Drawio | 8/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. | |
| Modificada | Media (5.4) | 0.63% | — | Diagrams Drawio | 5/9/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. | |
| Modificada | Alta (7.5) | 1.3% | — | Diagrams Drawio | 2/9/2022 | 17/6/2026 | Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. | |
| Modificada | Alta (7.8) | 0.40% | — | Opendesign Drawings SDK | 17/7/2022 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.42% | — | Opendesign Drawings SDK | 17/7/2022 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.42% | — | Opendesign Drawings SDK | 17/7/2022 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Media (5.4) | 0.64% | — | Diagrams Drawio | 9/6/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. | |
| Modificada | Media (5.4) | 0.73% | — | Diagrams Drawio | 9/6/2022 | 17/6/2026 | Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Diagrams Drawio | 25/5/2022 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. | |
| Modificada | Alta (7.5) | 1.8% | — | Diagrams Drawio | 20/5/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. | |
| Modificada | Media (4.6) | 0.61% | — | Diagrams Drawio | 19/5/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. | |
| Modificada | Media (6.1) | 1.2% | — | Diagrams Drawio | 18/5/2022 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. | |
| Modificada | Alta (7.5) | 1.8% | — | Diagrams Drawio | 18/5/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. | |
| Modificada | Alta (8.8) | 1.4% | — | Diagrams Drawio | 18/5/2022 | 17/6/2026 | Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6. |