Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.38% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Indesign | 9/6/2026 | 28/8/2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Aplazada | Alta (8.8) | 0.27% | — | WOW Viral SignupsAI | 9/6/2026 | 21/7/2026 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup'… | |
| Aplazada | Baja (2.1) | 0.21% | — | Designcomputer Mysql-mcp-serverAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible.… | |
| Aplazada | Crítica (9.3) | 0.26% | — | PDF SignerAI | 4/6/2026 | 22/7/2026 | PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute… | |
| Aplazada | Crítica (9.4) | 0.98% | — | Disig WEB SignerAI | 1/6/2026 | 22/7/2026 | A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. | |
| Aplazada | Alta (7.6) | 0.29% | — | Beyaz Computer Software Design Industry AND Trade CityplusAI | 20/5/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: before V24.29750.1.0. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Ids6 Dsspro Digital Signage SystemAI | 16/5/2026 | 17/6/2026 | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts. | |
| Aplazada | Media (5.4) | 0.17% | — | Sigstore GitsignAI | 15/5/2026 | 17/6/2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0] after sd.GetCertificates() without checking the slice length. A CMS/PKCS7 signed message with an empty… | |
| Aplazada | Media (5.3) | 0.16% | — | Go-gitAISigstore GitsignAI | 15/5/2026 | 17/6/2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git object bytes. For… | |
| Pendiente de análisis | Alta (7.4) | 0.25% | — | Redpine Signals Rs9116AI | 14/5/2026 | 17/6/2026 | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | |
| Modificada | Alta (7.8) | 0.26% | — | Adobe Substance 3D Designer | 12/5/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.26% | — | Adobe Substance 3D Designer | 12/5/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Substance 3D Designer | 12/5/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Substance 3D Designer | 12/5/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Media (6.3) | 0.29% | — | Adobe Substance 3D Designer | 12/5/2026 | 28/8/2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended… | |
| Aplazada | Alta (7.7) | 0.42% | 💥 PoC | Xibosignage XiboAI | 12/5/2026 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to… | |
| Aplazada | Media (6.4) | 0.32% | — | SP Blog DesignerAI | 12/5/2026 | 17/6/2026 | The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.7) | 0.51% | — | Signalk Signal K Server | 9/5/2026 | 24/7/2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path —… | |
| Analizada | Media (4.3) | 0.30% | — | Xibosignage Xibo | 24/4/2026 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the vulnerability is… | |
| Analizada | Media (4.9) | 0.48% | — | Xibosignage Xibo | 24/4/2026 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1 allows users with DataSet permissions to make arbitrary HTTP requests from the CMS server to internal or… | |
| Analizada | Media (5.4) | 0.24% | — | Xibosignage Xibo | 24/4/2026 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 allows an authenticated user with notification creation permissions to inject arbitrary JavaScript into the notification… |