Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | 💥 PoC | Opendesign Drawings SDK | 26/12/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.27% | — | Opendesign Drawings SDK | 7/11/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code… | |
| Modificada | Media (6.1) | 0.33% | — | Extendwings Opcache Dashboard | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Followingmedarling Spotify Play Button | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.10 versions. | |
| Modificada | Alta (8.8) | 0.56% | — | Wftpserver Wing FTP Server | 12/9/2023 | 17/6/2026 | Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | |
| Modificada | Alta (7.5) | 0.53% | — | Wftpserver Wing FTP Server | 12/9/2023 | 17/6/2026 | Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0. | |
| Modificada | Alta (8.8) | 0.51% | — | Wftpserver Wing FTP Server | 12/9/2023 | 17/6/2026 | Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. | |
| Modificada | Media (5.4) | 0.29% | — | Wftpserver Wing FTP Server | 12/9/2023 | 17/6/2026 | Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0. | |
| Modificada | Media (4.3) | 0.48% | — | Wpswings Ultimate Gift Cards FOR Woocommerce | 1/7/2023 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card… | |
| Modificada | Alta (8.8) | 0.92% | — | Pterodactyl Wings | 10/5/2023 | 17/6/2026 | Wings is the server control plane for Pterodactyl Panel. A vulnerability affecting versions prior to 1.7.5 and versions 1.11.0 prior to 1.11.6 impacts anyone running the affected versions of Wings. This vulnerability can be used to gain access to the host system running Wings if a user is able to modify an server's… | |
| Modificada | Alta (7.8) | 0.22% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length… | |
| Modificada | Alta (7.8) | 0.32% | — | Opendesign Drawings SDK | 15/4/2023 | 17/6/2026 | Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.44% | — | Opendesign Drawings SDK | 10/4/2023 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code. | |
| Modificada | Alta (8.2) | 0.96% | — | Pterodactyl Wings | 9/2/2023 | 17/6/2026 | Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an attacker must have an existing "server"… | |
| Modificada | Alta (8.8) | 0.68% | — | Pterodactyl Wings | 8/2/2023 | 17/6/2026 | Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to create new files and directory structures on the host system that previously did not exist, potentially allowing attackers to change their resource allocations, promote their containers to privileged… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Wpswings PDF Generator FOR Wordpress | 6/2/2023 | 17/6/2026 | The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | Wpswings Membership FOR Woocommerce | 30/1/2023 | 17/6/2026 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. | |
| Modificada | Media (4.3) | 0.31% | — | Wpswings Mautic Integration FOR Woocommerce | 9/1/2023 | 17/6/2026 | The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack. | |
| Modificada | Crítica (9.8) | 0.83% | — | Wing-tight Project Wing-tight | 5/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is… | |
| Modificada | Crítica (9.8) | 6.2% | 💥 PoC | Wpswings Return Refund AND Exchange FOR Woocommerce | 26/12/2022 | 17/6/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | |
| Modificada | Media (6.1) | 0.29% | — | Showing URL IN QR Code Project Showing URL IN QR Code | 28/11/2022 | 17/6/2026 | The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin or editor add Stored XSS payloads via a CSRF attack | |
| Modificada | Crítica (9.8) | 1.5% | — | Wisa Smart Wing CMS | 17/10/2022 | 17/6/2026 | This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal. | |
| Modificada | Alta (7.5) | 0.45% | — | Wisa Smart Wing CMS | 17/8/2022 | 17/6/2026 | This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system. | |
| Modificada | Alta (7.8) | 0.40% | — | Opendesign Drawings SDK | 17/7/2022 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.42% | — | Opendesign Drawings SDK | 17/7/2022 | 17/6/2026 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. |