Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

2143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.23%💥 PoCStimulsoft Designer27/3/20239/7/2026
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems.
ModificadaCrítica (9.8)1.9%💥 PoCStimulsoft DesignerStimulsoft Viewer27/3/20239/7/2026
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which…
ModificadaMedia (6.5)0.33%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
ModificadaMedia (6.5)0.44%—Miniorange Oauth Single Sign ON27/3/202317/6/2026
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP),…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is…
ModificadaMedia (6.1)0.56%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to…
ModificadaMedia (6.1)0.59%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. Affected is an unknown function of the file verification.php. The manipulation of the argument txtvaccinationID leads to cross site scripting. It is possible to…
ModificadaAlta (8.1)0.86%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The…
ModificadaAlta (8.8)1.1%—Upthemes Designfolio-plus7/3/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been…
ModificadaAlta (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+623/2/202317/6/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
ModificadaMedia (5.4)0.53%—Smg-webdesign Shortcode FOR Font Awesome21/2/202317/6/2026
The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.5)0.34%—Adobe Indesign17/2/202317/6/2026
Adobe InDesign versions ID18.1 (and earlier) and ID17.4 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user…
ModificadaAlta (8.8)0.26%—Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
ModificadaMedia (5.5)0.25%—Pesign Project PesignFedoraproject FedoraRedhat Enterprise Linux2/2/202317/6/2026
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This…
ModificadaMedia (6.5)0.71%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de lectura fuera de los límites debido a una validación insuficiente de la longitud del parámetro. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a contenido confidencial parcial en la memoria e interrumpir…
ModificadaCrítica (9.8)0.91%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de validación de entrada incorrecta. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder y modificar la subclave HKEY_CURRENT_USER (por ejemplo, AutoRUN) en el Registro, donde se pueden ejecutar scripts maliciosos…
ModificadaAlta (7.5)1.00%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de path traversal dentro de su función de lectura de archivos. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a archivos arbitrarios del sistema.
ModificadaMedia (5.4)0.63%—Solwininfotech Blog Designer30/1/202317/6/2026
El complemento Blog Designer de WordPress anterior a 2.4.1 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado.
ModificadaMedia (5.4)0.44%—Infornweb News & Blog Designer Pack30/1/202317/6/2026
El complemento News &amp; Blog Designer Pack de WordPress anterior a 3.3 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado.
AnalizadaMedia (5.4)0.47%—Infornweb Posts List Designer30/1/202317/6/2026
El complemento Posts List Designer by Category de WordPress anterior a 3.2 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían ser…
ModificadaMedia (6.1)0.61%—Miniorange Saml SP Single Sign ON30/1/202317/6/2026
El complemento SAML SSO Standard de WordPress versión 16.0.0 anterior a 16.0.8, el complemento SAML SSO Premium de WordPress versión 12.0.0 anterior a 12.1.0 y el complemento SAML SSO Premium Multisite de WordPress versión 20.0.0 anterior a 20.0.7 no validan que el parámetro de redireccionamiento a su punto final de…
ModificadaAlta (7.8)0.30%—Qlik Nprinting Designer26/1/202317/6/2026
Qlik NPrinting Designer hasta 21.14.3.0 crea un archivo temporal en un directorio con permisos inseguros.
ModificadaBaja (3.3)0.86%—Signal-desktop23/1/202317/6/2026
Signal Desktop anterior a 6.2.0 en Windows, Linux y macOS permite a un atacante obtener archivos adjuntos potencialmente confidenciales enviados en mensajes desde el directorio attachments.noindex. Los archivos adjuntos almacenados en caché no se borran de manera efectiva. En algunos casos, incluso después de la…
ModificadaAlta (7.8)0.37%—Signal-desktop23/1/202317/6/2026
Signal Desktop anterior a 6.2.0 en Windows, Linux y macOS permite a un atacante modificar archivos adjuntos de conversaciones dentro del directorio attachments.noindex. Los mecanismos del cliente no logran validar las modificaciones de los archivos almacenados en caché existentes, lo que da como resultado la capacidad…