Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.86% | — | Adobe Creative Cloud | 8/9/2021 | 17/6/2026 | Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local machine. | |
| Modificada | Media (6.1) | 0.49% | — | Adobe Creative Cloud Desktop Application | 24/8/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overwriting in the context of the current user. Exploitation of this issue requires physical interaction… | |
| Modificada | Alta (7.8) | 2.7% | — | Adobe Creative Cloud Desktop Application | 24/8/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | |
| Modificada | Media (5.9) | 1.3% | — | Creative Pebble V3 FirmwareCreative Pebble V2 FirmwareCreative Pebble FirmwareCreative Pebble Plus Firmware | 11/8/2021 | 17/6/2026 | CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power… | |
| Modificada | Media (4.9) | 1.1% | — | Ethercreative Logs | 9/7/2021 | 17/6/2026 | Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if… | |
| Modificada | Media (6.5) | 1.1% | — | Adobe Creative Cloud Desktop Application | 12/3/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction | |
| Modificada | Alta (7.8) | 2.6% | — | Adobe Creative Cloud Desktop Application | 12/3/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction. | |
| Modificada | Media (6.1) | 0.62% | — | Adobe Creative Cloud Desktop Application | 12/3/2021 | 17/6/2026 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that could allow an attacker to cause arbitrary file overwriting. Exploitation of this issue requires physical access and user interaction. | |
| Modificada | Crítica (9.8) | 28% | 💥 Exploit | Alleghenycreative Openrepeater | 19/2/2021 | 17/6/2026 | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. | |
| Modificada | Media (6.5) | 0.41% | — | Creativeitem Neoflex Video Subscription System | 4/11/2020 | 17/6/2026 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) | |
| Modificada | Alta (7.8) | 3.1% | — | Adobe Creative Cloud | 21/10/2020 | 17/6/2026 | Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open… | |
| Modificada | Crítica (9.8) | 4.3% | — | Adobe Creative Cloud Desktop Application | 17/7/2020 | 17/6/2026 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to arbitrary file system write. | |
| Modificada | Crítica (9.8) | 4.0% | — | Adobe Creative Cloud Desktop Application | 17/7/2020 | 17/6/2026 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Crítica (9.8) | 3.6% | — | Adobe Creative Cloud Desktop Application | 17/7/2020 | 17/6/2026 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Crítica (9.8) | 3.4% | — | Adobe Creative Cloud | 17/7/2020 | 17/6/2026 | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Media (5.9) | 1.4% | — | Adobe Creative Cloud | 25/3/2020 | 17/6/2026 | Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerability. Successful exploitation could lead to arbitrary file deletion. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (5.3) | 3.1% | — | Creative-solutions Creative Contact Form | 4/3/2020 | 17/6/2026 | An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send… | |
| Modificada | Crítica (9.8) | 92% | 💥 Exploit | Creative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload | 8/2/2020 | 17/6/2026 | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by… | |
| Modificada | Crítica (9.8) | 3.4% | — | Adobe Creative Cloud | 23/10/2019 | 17/6/2026 | Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Angrycreative BJ Lazy Load | 26/9/2019 | 17/6/2026 | The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion. | |
| Modificada | Media (6.1) | 1.0% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload. | |
| Modificada | Alta (7.5) | 2.2% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. | |
| Modificada | Alta (7.5) | 3.7% | — | Adobe Creative Cloud | 16/8/2019 | 17/6/2026 | Creative Cloud Desktop Application 4.6.1 and earlier versions have an insecure transmission of sensitive data vulnerability. Successful exploitation could lead to information leakage. |