Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.22%—SAP Powerdesigner8/8/202317/6/2026
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application.
ModificadaMedia (6.1)0.35%—Admiror-design-studio Admiror Gallery7/8/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
ModificadaMedia (5)1.3%💥 PoCRedhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+14/8/202317/6/2026
Se ha encontrado un fallo en la autenticación de usuarios en OpenID Connect de Keycloak, que podría autenticar incorrectamente las solicitudes. Un atacante autenticado que pudiera obtener información de una solicitud de usuario dentro del mismo entorno, podría utilizar esos datos para hacerse pasar por la víctima y…
ModificadaAlta (7.5)0.68%—Mitsubishielectric GT Designer3Mitsubishielectric GT Softgot2000Mitsubishielectric Gt27 FirmwareMitsubishielectric Gt25 Firmware+44/8/202317/6/2026
Vulnerabilidad Weak Encoding for Password en Mitsubishi Electric Corporation GOT2000 Series modelo GT27 versiones 01.49.000 y anteriores, modelo GT25 versiones 01.49.000 y anteriores, modelo GT23 versiones 01.49.000 y anteriores, modelo GT21 versiones 01.49.000 y anteriores, serie GOT SIMPLE modelo GS25 versiones…
ModificadaAlta (7.8)0.29%—Adobe Indesign20/7/202317/6/2026
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.
ModificadaAlta (8.8)0.96%💥 PoCMiniorange Oauth Single Sign ON18/7/202317/6/2026
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
ModificadaAlta (8.8)0.32%—Etoilewebdesign Front END Users17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions.
ModificadaMedia (4.3)0.45%—Jenkins Saml Single Sign ON12/7/202317/6/2026
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.47%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.46%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaMedia (5.5)0.47%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a…
ModificadaAlta (7.8)0.42%—Adobe Indesign12/7/202317/6/2026
Adobe InDesign versiones ID18.3 (y anteriores) y ID17.4.1 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la…
ModificadaMedia (6.1)0.44%—Webdesignmunich Mail Queue12/7/202317/6/2026
The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (4.3)0.38%—Coolplugins Process Steps Template Designer12/7/202317/6/2026
The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request…
ModificadaMedia (4.3)0.38%—Designwall DW Question & Answer12/7/202317/6/2026
The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.8. This is due to missing or incorrect nonce validation on the update_answer() function. This makes it possible for unauthenticated attackers to update answers to questions via a forged…
ModificadaMedia (4.8)0.54%—Stpetedesign Call NOW Accessibility Button10/7/202317/6/2026
The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.50%—Stpetedesign Call NOW Accessibility Button10/7/202317/6/2026
The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).