Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Ekushey Project Manager | 19/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch… | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Mastery LMS | 19/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Creativeitem Mastery LMS 1.2. This affects an unknown part of the file /browse. The manipulation of the argument search/featured/recommended/skill leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Academy LMS | 19/7/2023 | 17/6/2026 | A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home/courses. The manipulation of the argument sort_by leads to cross site scripting. The attack may be launched remotely. VDB-234422 is the identifier… | |
| Modificada | Media (4.8) | 0.54% | — | Punchcreative GET Your Number | 5/6/2023 | 17/6/2026 | The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.55% | — | Creativethemes Blocksy Companion | 2/5/2023 | 17/6/2026 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example | |
| Modificada | Media (5.4) | 0.43% | — | Bnecreative BNE Testimonials | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kerry Kline BNE Testimonials plugin <= 2.0.7 versions. | |
| Modificada | Media (5.4) | 0.34% | — | Creativethemes Blocksy Companion | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. | |
| Modificada | Alta (7.8) | 0.43% | — | Wondershare Creative Centerr | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file. | |
| Modificada | Alta (7.8) | 0.36% | — | Adobe Creative Cloud | 22/3/2023 | 17/6/2026 | Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs,… | |
| Modificada | Alta (8.8) | 0.86% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. | |
| Modificada | Media (4.8) | 0.41% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. | |
| Modificada | Media (4.3) | 0.62% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. | |
| Modificada | Alta (8.8) | 0.31% | — | Constantcontact Creative Mail | 18/11/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress. | |
| Modificada | Alta (8.8) | 0.76% | — | Constantcontact Creative Mail | 18/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. | |
| Modificada | Alta (8.8) | 0.29% | — | Constantcontact Creative Mail | 18/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. | |
| Modificada | Crítica (9.8) | 1.4% | — | Creativedream File Uploader Project Creativedream File Uploader | 3/10/2022 | 17/6/2026 | Arbitrary file upload vulnerability in php uploader | |
| Modificada | Media (6.1) | 3.0% | 💥 Exploit | Creativeitem Academy Learning Management System | 26/9/2022 | 9/7/2026 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |
| Modificada | Media (5.4) | 0.60% | — | Room 34 Creative Services Enable SVG | 30/5/2022 | 17/6/2026 | The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads | |
| Modificada | Media (4.8) | 0.62% | 💥 PoC | Creativeitem Academy LMS | 25/5/2022 | 17/6/2026 | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. | |
| Modificada | Alta (7) | 2.2% | — | Adobe Creative Cloud Desktop Application | 16/2/2022 | 17/6/2026 | Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The… | |
| Modificada | Media (4.9) | 14% | 💥 Exploit | Ethercreative Logs | 31/1/2022 | 17/6/2026 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | |
| Modificada | Alta (7.8) | 2.2% | — | Adobe Creative Cloud Desktop Application | 23/11/2021 | 17/6/2026 | Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the… | |
| Modificada | Media (4.2) | 1.2% | — | Adobe Creative Cloud Desktop Application | 18/11/2021 | 17/6/2026 | Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local… | |
| Modificada | Alta (7.8) | 0.52% | — | Adobe Creative Cloud Desktop Application | 29/9/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority. | |
| Modificada | Alta (7.4) | 0.49% | — | Adobe Creative Cloud Desktop Application | 27/9/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that could allow an attacker to arbitrarily overwrite a file. Exploitation of this issue requires local access, administrator privileges and user interaction. |