Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

2143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.21%—Jenkins Saml Single Sign ON16/5/202317/6/2026
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
ModificadaAlta (8.8)0.83%—Jenkins Saml Single Sign ON16/5/202317/6/2026
Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.
ModificadaAlta (8.8)0.68%—Jenkins Saml Single Sign ON16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.
ModificadaMedia (5.4)0.36%—WEB Design Easy Sign UP Project WEB Design Easy Sign UP10/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Andrew @ Geeenville Web Design Easy Sign Up plugin <= 3.4.1 versions.
ModificadaAlta (7.5)0.64%—SAP Powerdesigner Proxy9/5/202317/6/2026
In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application.
ModificadaMedia (4.6)1.2%—HP Designjet Z6 FirmwareHP Designjet Z6dr FirmwareHP Designjet Z9 FirmwareHP Designjet Z9dr Firmware+628/4/202317/6/2026
Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.
ModificadaAlta (7.8)0.22%—Opendesign Drawings SDK15/4/202317/6/2026
A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length…
ModificadaAlta (7.8)0.32%—Opendesign Drawings SDK15/4/202317/6/2026
Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.41%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.30%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.38%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.41%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.41%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.34%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.…
ModificadaAlta (7.8)0.38%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaAlta (7.8)0.34%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.…
ModificadaAlta (7.8)0.34%—Adobe Substance 3D Designer13/4/202317/6/2026
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.…
ModificadaAlta (7.8)0.44%—Opendesign Drawings SDK10/4/202317/6/2026
An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.
ModificadaCrítica (9.8)0.90%—Cdesigner Project Cdesigner7/4/202317/6/2026
Se ha descubierto que Prestashop cdesigner v3.1.3 a v3.1.8 contiene una vulnerabilidad de inyección de código en el componente CdesignerSaverotateModuleFrontController::initContent().
ModificadaMedia (5.4)0.38%—Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
ModificadaMedia (5.4)0.70%💥 PoCRedhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform29/3/202317/6/2026
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
ModificadaAlta (7.5)0.84%💥 PoCStimulsoft Designer28/3/20239/7/2026
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
ModificadaAlta (7.5)0.90%💥 PoCStimulsoft Designer28/3/20239/7/2026
Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the…
ModificadaAlta (8.1)0.91%—React-native-onesignal27/3/202317/6/2026
OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on…
ModificadaMedia (6.1)0.40%—Redhat Keycloak Node.js AdapterRedhat Single Sign-on27/3/202317/6/2026
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.