Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

137 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.32%—Solidworks EdrawingsAI4/4/202417/6/2026
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT…
ModificadaCrítica (9.8)0.49%—Wpswings Points AND Rewards FOR Woocommerce25/3/202417/6/2026
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
AnalizadaAlta (8.5)0.55%—Pterodactyl Wings13/3/202417/6/2026
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope of impact is exactly unknown, but reading files outside of a server's base…
ModificadaCrítica (9.8)0.77%—Wpswings Coupon Referral Program12/2/202417/6/2026
Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.
ModificadaAlta (7.5)0.52%—Wpswings Coupon Referral Program8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.
ModificadaAlta (7.8)0.19%💥 PoCOpendesign Drawings SDK26/12/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.27%—Opendesign Drawings SDK7/11/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code…
ModificadaMedia (6.1)0.33%—Extendwings Opcache Dashboard18/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.
ModificadaMedia (4.3)0.48%—Wpswings Ultimate Gift Cards FOR Woocommerce1/7/202317/6/2026
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card…
ModificadaAlta (8.8)0.92%—Pterodactyl Wings10/5/202317/6/2026
Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected versions of Wings. This vulnerability can be used to gain access to the host system running Wings if a user is able to modify an server's…
ModificadaAlta (7.8)0.22%—Opendesign Drawings SDK15/4/202317/6/2026
A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length…
ModificadaAlta (7.8)0.32%—Opendesign Drawings SDK15/4/202317/6/2026
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.44%—Opendesign Drawings SDK10/4/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
ModificadaAlta (8.2)0.96%—Pterodactyl Wings9/2/202317/6/2026
Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an attacker must have an existing "server"…
ModificadaAlta (8.8)0.68%—Pterodactyl Wings8/2/202317/6/2026
Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged…
ModificadaMedia (6.1)1.2%💥 ExploitWpswings PDF Generator FOR Wordpress6/2/202317/6/2026
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
ModificadaCrítica (9.8)18%💥 ExploitWpswings Membership FOR Woocommerce30/1/202317/6/2026
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
ModificadaMedia (4.3)0.31%—Wpswings Mautic Integration FOR Woocommerce9/1/202317/6/2026
The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.
ModificadaCrítica (9.8)6.2%💥 PoCWpswings Return Refund AND Exchange FOR Woocommerce26/12/202217/6/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
ModificadaAlta (7.8)0.40%—Opendesign Drawings SDK17/7/202217/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.42%—Opendesign Drawings SDK17/7/202217/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.42%—Opendesign Drawings SDK17/7/202217/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)1.1%—Opendesign Drawings Software Development KIT15/1/202217/6/2026
Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.82%—Opendesign Drawings SDK21/12/202117/6/2026
An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in…
ModificadaAlta (7.8)0.82%—Opendesign Drawings SDK21/12/202117/6/2026
An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An unchecked input data from a crafted TGA file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in…
Orbitaley — Vulnerabilidades