Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.6% | — | Adobe After Effects | 25/6/2020 | 17/6/2026 | Adobe After Effects versions 17.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 3.3% | — | Adobe After Effects | 25/6/2020 | 17/6/2026 | Adobe After Effects versions 17.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 8.7% | — | Adobe After Effects | 25/6/2020 | 17/6/2026 | Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Alta (7.8) | 8.4% | — | Adobe After Effects | 25/6/2020 | 17/6/2026 | Adobe After Effects versions 17.1 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution . | |
| Modificada | Crítica (9.8) | 4.2% | — | Effect Project Effect | 2/4/2020 | 17/6/2026 | effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. | |
| Modificada | Crítica (9.8) | 5.6% | — | Adobe After Effects | 20/2/2020 | 17/6/2026 | Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 3.2% | — | Adobe After Effects | 14/8/2019 | 17/6/2026 | Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Media (4.3) | 2.0% | — | Banner Effect Header Project Banner Effect Header | 3/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php. | |
| Modificada | Media (6.8) | 1.2% | — | Banner Effect Header Project Banner Effect Header | 8/1/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to… | |
| Modificada | Media (5) | 2.4% | — | Blinkwebeffects Social-media-widget | 25/4/2013 | 16/6/2026 | Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Zooeffect | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wp-1pluginjquery.php in the ZooEffect plugin 1.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: some of these details are obtained from third party information. NOTE: this has been disputed by a third party. | |
| Modificada | Media (6.9) | 0.36% | — | Sowsoft Effective File Search | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Effective File Search 6.7 allows local users to gain privileges via a Trojan horse ztvunrar36.dll file in the current working directory, as demonstrated by a directory that contains a .efs file. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Sumeffect Digishop | 30/12/2010 | 16/6/2026 | SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vulnerability than CVE-2005-4614.1. | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Effectmatrix Magic Morph | 24/9/2009 | 16/6/2026 | Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Effectmatrix Total Video Player | 23/1/2009 | 16/6/2026 | Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | SUM Effect Software Digishop | 5/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | SUM Effect Software Digishop | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in digiSHOP 3.1.17 and earlier allow remote attackers to execute arbitrary SQL commands or obtain the full installation path via (1) the c parameter in cart.php and (2) unspecified search module parameters. |