Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.36%—Creativeitem Ekushey Project Manager19/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch…
ModificadaMedia (6.1)0.36%—Creativeitem Mastery LMS19/7/202317/6/2026
A vulnerability classified as problematic has been found in Creativeitem Mastery LMS 1.2. This affects an unknown part of the file /browse. The manipulation of the argument search/featured/recommended/skill leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this…
ModificadaMedia (6.1)0.36%—Creativeitem Academy LMS19/7/202317/6/2026
A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home/courses. The manipulation of the argument sort_by leads to cross site scripting. The attack may be launched remotely. VDB-234422 is the identifier…
ModificadaMedia (4.8)0.54%—Punchcreative GET Your Number5/6/202317/6/2026
The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.3)0.55%—Creativethemes Blocksy Companion2/5/202317/6/2026
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
ModificadaMedia (5.4)0.43%—Bnecreative BNE Testimonials6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kerry Kline BNE Testimonials plugin <= 2.0.7 versions.
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy Companion6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
ModificadaAlta (7.8)0.43%—Wondershare Creative Centerr4/4/202317/6/2026
An issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wondershareCC_setup_full10819.exe file.
ModificadaAlta (7.8)0.36%—Adobe Creative Cloud22/3/202317/6/2026
Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs,…
ModificadaAlta (8.8)0.86%💥 PoCCreativeitem Academy LMS3/2/202317/6/2026
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
ModificadaMedia (4.8)0.41%💥 PoCCreativeitem Academy LMS3/2/202317/6/2026
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
ModificadaMedia (4.3)0.62%💥 PoCCreativeitem Academy LMS3/2/202317/6/2026
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.
ModificadaAlta (8.8)0.31%—Constantcontact Creative Mail18/11/202217/6/2026
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.
ModificadaAlta (8.8)0.76%—Constantcontact Creative Mail18/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
ModificadaAlta (8.8)0.29%—Constantcontact Creative Mail18/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
ModificadaCrítica (9.8)1.4%—Creativedream File Uploader Project Creativedream File Uploader3/10/202217/6/2026
Arbitrary file upload vulnerability in php uploader
ModificadaMedia (6.1)3.0%💥 ExploitCreativeitem Academy Learning Management System26/9/20229/7/2026
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
ModificadaMedia (5.4)0.60%—Room 34 Creative Services Enable SVG30/5/202217/6/2026
The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
ModificadaMedia (4.8)0.62%💥 PoCCreativeitem Academy LMS25/5/202217/6/2026
Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
ModificadaAlta (7)2.2%—Adobe Creative Cloud Desktop Application16/2/202217/6/2026
Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The…
ModificadaMedia (4.9)14%💥 ExploitEthercreative Logs31/1/202217/6/2026
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
ModificadaAlta (7.8)2.2%—Adobe Creative Cloud Desktop Application23/11/202117/6/2026
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the…
ModificadaMedia (4.2)1.2%—Adobe Creative Cloud Desktop Application18/11/202117/6/2026
Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local…
ModificadaAlta (7.8)0.52%—Adobe Creative Cloud Desktop Application29/9/202117/6/2026
Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a normal user to delete the OOBE directory and get permissions of any directory under the administrator authority.
ModificadaAlta (7.4)0.49%—Adobe Creative Cloud Desktop Application27/9/202117/6/2026
Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that could allow an attacker to arbitrarily overwrite a file. Exploitation of this issue requires local access, administrator privileges and user interaction.
Orbitaley — Vulnerabilidades