Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

2143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.63%💥 PoCRedhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+17/7/202317/6/2026
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
ModificadaAlta (7.8)0.30%—Osslsigncode Project Osslsigncode3/7/202317/6/2026
Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary code via a crafted .exe, .sys, and .dll files.
ModificadaMedia (4.8)0.50%—Etoilewebdesign Ultimate Product Catalog27/6/202317/6/2026
The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)0.35%—Adobe Substance 3D Designer15/6/202317/6/2026
Adobe Substance 3D Designer version 12.4.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaMedia (4.8)0.37%—Designextreme We're Open!13/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46 versions.
ModificadaMedia (4.8)0.37%—Stpetedesign Call NOW Accessibility Button12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in StPeteDesign Call Now Accessibility Button plugin <= 1.1 versions.
ModificadaAlta (8.8)0.56%—Coolplugins Process Steps Template Designer7/6/202317/6/2026
The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such…
ModificadaCrítica (9.8)1.6%—Etoilewebdesign Ultimate Reviews7/6/202317/6/2026
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
ModificadaMedia (4.6)0.70%—Xootix Login/signup Popup7/6/202317/6/2026
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can…
ModificadaAlta (7.5)3.6%💥 ExploitTshirtecommerce Custom Product Designer1/6/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without…
ModificadaAlta (7.5)3.6%💥 ExploitTshirtecommerce Custom Product Designer1/6/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files…
ModificadaMedia (5.3)0.54%—Xibosignage Xibo30/5/202317/6/2026
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which…
ModificadaMedia (6.5)0.62%—Xibosignage Xibo30/5/202317/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the…
ModificadaMedia (6.5)0.62%—Xibosignage Xibo30/5/202317/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for…
ModificadaMedia (6.5)0.63%—Xibosignage Xibo30/5/202317/6/2026
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API route inside the CMS starting in version 1.4.0 and prior to versions 2.3.17 and 3.3.5. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted…
ModificadaAlta (8.8)7.0%💥 ExploitXibosignage Xibo30/5/202317/6/2026
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the webserver user. This…
ModificadaCrítica (9.1)0.39%—Moov Signedxml30/5/202317/6/2026
En Moov signedxml hasta la versión 1.0.0, el análisis del XML sin procesar (tal y como se recibe) puede dar lugar a resultados diferentes que el análisis del XML procesado y canonicalizado. Por lo tanto, la validación de la firma puede eludirse mediante un ataque de envoltura de firma (también conocido como XSW).
ModificadaAlta (7.5)1.1%—Signalwire Sofia-sipDebian Linux26/5/202317/6/2026
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and…
ModificadaMedia (6.5)0.43%—Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+126/5/202317/6/2026
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the…
ModificadaAlta (8.8)0.26%—Orion Woocommerce Products Designer25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions.
ModificadaMedia (5.5)0.23%—Simpledesign Diary With Lock\24/5/202317/6/2026
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the…
ModificadaCrítica (9.8)0.76%—Cdesigner Project Cdesigner17/5/202317/6/2026
PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().
ModificadaMedia (4.3)0.43%—Jenkins Saml Single Sign-on16/5/202317/6/2026
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.
ModificadaAlta (8.8)0.45%—Jenkins Saml Single Sign ON16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.
ModificadaBaja (3.7)0.24%—Jenkins Saml Single Sign ON16/5/202317/6/2026
Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.