Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.21% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections. | |
| Modificada | Alta (8.8) | 0.83% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | |
| Modificada | Media (5.4) | 0.36% | — | WEB Design Easy Sign UP Project WEB Design Easy Sign UP | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Andrew @ Geeenville Web Design Easy Sign Up plugin <= 3.4.1 versions. | |
| Modificada | Alta (7.5) | 0.64% | — | SAP Powerdesigner Proxy | 9/5/2023 | 17/6/2026 | In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application. | |
| Modificada | Media (4.6) | 1.2% | — | HP Designjet Z6 FirmwareHP Designjet Z6dr FirmwareHP Designjet Z9 FirmwareHP Designjet Z9dr Firmware+6 | 28/4/2023 | 17/6/2026 | Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer. | |
| Modificada | Alta (7.8) | 0.22% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length… | |
| Modificada | Alta (7.8) | 0.32% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.44% | — | Opendesign Drawings SDK | 10/4/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdesigner Project Cdesigner | 7/4/2023 | 17/6/2026 | Se ha descubierto que Prestashop cdesigner v3.1.3 a v3.1.8 contiene una vulnerabilidad de inyección de código en el componente CdesignerSaverotateModuleFrontController::initContent(). | |
| Modificada | Media (5.4) | 0.38% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 29/3/2023 | 17/6/2026 | A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users. | |
| Modificada | Alta (7.5) | 0.84% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. | |
| Modificada | Alta (7.5) | 0.90% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the… | |
| Modificada | Alta (8.1) | 0.91% | — | React-native-onesignal | 27/3/2023 | 17/6/2026 | OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on… | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Keycloak Node.js AdapterRedhat Single Sign-on | 27/3/2023 | 17/6/2026 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. |