Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | Iqonicdesign Wpbookit PROAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Media (5.3) | 0.24% | — | Designinvento DirectorypressAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.25. | |
| Aplazada | Media (6.4) | 0.26% | — | Ravelry Designs WidgetAI | 14/2/2026 | 17/6/2026 | The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute of the 'sb_ravelry_designs' shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Crítica (9.4) | 0.39% | — | E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record… | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Indesign | 10/2/2026 | 28/8/2026 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction… | |
| Analizada | Alta (7.8) | 0.24% | — | Adobe Indesign | 10/2/2026 | 28/8/2026 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Media (5.5) | 0.15% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in… | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Analizada | Media (5.5) | 0.15% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in… | |
| Analizada | Alta (7.8) | 0.20% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.20% | — | Adobe Substance 3D Designer | 10/2/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (5.5) | 0.16% | — | Adobe Indesign | 10/2/2026 | 28/8/2026 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Aplazada | Media (6.5) | 0.23% | — | Pencidesign Penci PAY WriterAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Pay Writer penci-pay-writer allows Stored XSS.This issue affects Penci Pay Writer: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.23% | — | Pencidesign Penci ReviewAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Review penci-review allows Stored XSS.This issue affects Penci Review: from n/a through <= 3.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Harmonicdesign HD QuizAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz: from n/a through <= 2.0.9. | |
| Aplazada | Media (6.5) | 0.15% | — | Pencidesign Penci ShortcodesAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through <= 6.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Designthemes Dt-reservation-pluginAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reservation Plugin: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.41% | — | Designthemes OnelifeAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9. | |
| Aplazada | Alta (8.6) | 0.60% | — | Harmonicdesign HdformsAI | 22/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issue affects HDForms: from n/a through <= 1.6.1. | |
| Aplazada | Alta (8.8) | 0.47% | — | Designthemes VivaghAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Designingmedia HostikoAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 94.3.6. | |
| Aplazada | Alta (8.8) | 0.64% | — | Designthemes Kids HeavenAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through <= 3.2. |