Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.0% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory. | |
| Modificada | Crítica (9.8) | 4.8% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. | |
| Modificada | Alta (7.8) | 0.22% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application. | |
| Modificada | Alta (7.5) | 0.68% | — | Mitsubishielectric GT Designer3Mitsubishielectric GT Softgot2000Mitsubishielectric Gt27 FirmwareMitsubishielectric Gt25 Firmware+4 | 4/8/2023 | 17/6/2026 | Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21… | |
| Modificada | Media (4.3) | 0.38% | — | Coolplugins Process Steps Template Designer | 12/7/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request… | |
| Modificada | Alta (7.8) | 0.35% | — | Adobe Substance 3D Designer | 15/6/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (8.8) | 0.56% | — | Coolplugins Process Steps Template Designer | 7/6/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 1/6/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 1/6/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files… | |
| Modificada | Alta (8.8) | 0.26% | — | Orion Woocommerce Products Designer | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions. | |
| Modificada | Crítica (9.8) | 0.76% | — | Cdesigner Project Cdesigner | 17/5/2023 | 17/6/2026 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). | |
| Modificada | Alta (7.5) | 0.64% | — | SAP Powerdesigner Proxy | 9/5/2023 | 17/6/2026 | In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.41% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.38% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Designer | 13/4/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user.… | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdesigner Project Cdesigner | 7/4/2023 | 17/6/2026 | Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent(). | |
| Modificada | Alta (7.5) | 0.84% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion. | |
| Modificada | Alta (7.5) | 0.90% | 💥 PoC | Stimulsoft Designer | 28/3/2023 | 9/7/2026 | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the… | |
| Modificada | Media (5.5) | 0.23% | 💥 PoC | Stimulsoft Designer | 27/3/2023 | 9/7/2026 | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrypt any connectionstring stored in .mrt files since a static secret is used. The secret does not differ between the tested versions and different operating systems. |